Package: squid3
Severity: important
Tags: security

Squid3's error page CSS retrieves an image from www.squid-cache.org by default:

background: url('http://www.squid-cache.org/Artwork/SN.png') no-repeat left;

Although squid-cache.org delivers the image in a way that it should be cached forever, it could be used to gather various information about squid users and URLs they wanted to visit.

Shipping and delivering the image from within squid should not be too hard.


--
Mit freundlichen Grüßen


Bernd Zeimetz
Systems Engineer
Debian Developer

conova communications GmbH
Web    | http://www.conova.com/
E-Mail | b.zeim...@conova.com

Zentrale Salzburg
Karolingerstraße 36A
5020 Salzburg

Tel | +43 (0) 662 22 00 - 313
Fax | +43 (0) 662 22 00 - 209

Es gelten die Allgemeinen Geschäftsbedingungen der
conova communications GmbH, http://www.conova.com/de/agb/

Attachment: smime.p7s
Description: S/MIME cryptographic signature

Reply via email to