Re: FreeBSD Ports Security Advisory FreeBSD-SA-02:12.squid

From: Chris Faulhaber (jedgar@fxp.org)
Date: 02/21/02


Date: Thu, 21 Feb 2002 10:09:25 -0500
From: Chris Faulhaber <jedgar@fxp.org>
To: Alberto Manzoni <alberto.manzoni@univr.it>


On Thu, Feb 21, 2002 at 04:00:46PM +0100, Alberto Manzoni wrote:
> >4) No workaround exists for the HTCP issue except to set up a firewall
> >rule to block incoming packets to the Squid HTCP port (normally, UDP
> >port 4827) from untrusted hosts.
>
> No way setting htcp_port 0 ??
>

Not according to the advisory released by the squid developers
(and referenced in our advisory):

http://www.squid-cache.org/Advisories/SQUID-2002_1.txt

-- 
Chris D. Faulhaber - jedgar@fxp.org - jedgar@FreeBSD.org
--------------------------------------------------------
FreeBSD: The Power To Serve   -   http://www.FreeBSD.org

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Quantcast