Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Mageia: 2018-0458 Critical Squid XSS And DoS Security Alert

mageia
Calendar Grey November 17, 2018
Dist Mageia Esm H88
The 3.5.26 security patch for Squid tackles vulnerabilities related to cross-site scripting and risks of denial of service, providing robust solutions for these issues.
Due to incorrect input handling, Squid is vulnerable to a Cross-Site Scripting vulnerability when generating HTTPS response messages about TLS errors (CVE-2018-19131)

Summary

Due to incorrect input handling, Squid is vulnerable to a Cross-Site Scripting vulnerability when generating HTTPS response messages about TLS errors (CVE-2018-19131).
Due to a memory leak in SNMP query rejection code, Squid is vulnerable to a denial of service attack (CVE-2018-19132).

References

- https://bugs.mageia.org/show_bug.cgi?id=23780

- http://www.squid-cache.org/Advisories/SQUID-2018_4.txt

- http://www.squid-cache.org/Advisories/SQUID-2018_5.txt

- https://www.openwall.com/lists/oss-security/2018/11/09/1

- https://www.cve.org/CVERecord?id=CVE-2018-19131

- https://www.cve.org/CVERecord?id=CVE-2018-19132

Resolution

SRPMS

- 6/core/squid-3.5.26-1.2.mga6

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 17 Nov 2018
URL: https://advisories.mageia.org/MGASA-2018-0458.html
Type: security
CVE: CVE-2018-19131, CVE-2018-19132

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here