Debian: New squid packages fix denial of service

It was discovered that malformed cache update replies against the Squid WWW proxy cache could lead to the exhaustion of system memory, resulting in potential denial of service. Fixed packages are available from
Debian Security Advisory DSA-1482-1                               Moritz Muehlenhoff
February 05, 2008           
Package        : squid
Vulnerability  : programming error
Problem type   : remote
Debian-specific: no
CVE Id(s)      : CVE-2007-6239

For the stable distribution (etch), this problem has been fixed in
version 2.6.5-6etch1.

For the old stable distribution (sarge), the update cannot currently
be processed on the buildd security network due to a bug in the archive
management script. This will be resolved soon. An update for i386
is temporarily available at at

We recommend that you upgrade your squid packages.

Upgrade instructions
wget url
       will fetch the file for you
dpkg -i file.deb
       will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
       will update the internal database
apt-get upgrade
       will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.

Debian 4.0 (stable)
Stable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.

 These files will probably be moved into the stable distribution on
 its next update.

