DSA-966-1 adzapper -- denial of service

Related Vulnerabilities: CVE-2006-0046  

Thomas Reifferscheid discovered that adzapper, a proxy advertisement zapper add-on, when installed as plugin in squid, the Internet object cache, can consume a lot of CPU resources and hence cause a denial of service on the proxy host. The old stable distribution (woody) does not contain an adzapper package. For the stable distribution (sarge) this problem has been fixed in version 20050316-1sarge1. For the unstable distribution (sid) this problem has been fixed in version 20060115-1. We recommend that you upgrade your adzapper package.

Debian Security Advisory

DSA-966-1 adzapper -- denial of service

Date Reported:
09 Feb 2006
Affected Packages:
adzapper
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 350308.
In Mitre's CVE dictionary: CVE-2006-0046.
More information:

Thomas Reifferscheid discovered that adzapper, a proxy advertisement zapper add-on, when installed as plugin in squid, the Internet object cache, can consume a lot of CPU resources and hence cause a denial of service on the proxy host.

The old stable distribution (woody) does not contain an adzapper package.

For the stable distribution (sarge) this problem has been fixed in version 20050316-1sarge1.

For the unstable distribution (sid) this problem has been fixed in version 20060115-1.

We recommend that you upgrade your adzapper package.

Fixed in:

Debian GNU/Linux 3.1 (sarge)

Source:
http://security.debian.org/pool/updates/main/a/adzapper/adzapper_20050316-1sarge1.dsc
http://security.debian.org/pool/updates/main/a/adzapper/adzapper_20050316-1sarge1.diff.gz
http://security.debian.org/pool/updates/main/a/adzapper/adzapper_20050316.orig.tar.gz
Architecture-independent component:
http://security.debian.org/pool/updates/main/a/adzapper/adzapper_20050316-1sarge1_all.deb

MD5 checksums of the listed files are available in the original advisory.