Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Mageia 7: MGASA-2020-0187 Moderate: Squid Remote Code Execution Threat

mageia
Calendar Grey May 5, 2020
Dist Mageia Esm H88
Recent squid updates for Mageia address significant security vulnerabilities that could lead to remote code execution and the possibility of replay attacks on credentials.
Updated squid packages fix security vulnerability: Due to an integer overflow bug Squid is vulnerable to credential replay and remote code execution attacks against HTTP Digest Au...

Summary

Updated squid packages fix security vulnerability:
Due to an integer overflow bug Squid is vulnerable to credential replay and remote code execution attacks against HTTP Digest Authentication tokens. When memory pooling is used this problem allows a remote client to replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. When memory pooling is disabled this problem allows a remote client to perform remote code execution through the free'd nonce credentials (CVE-2020-11945).

References

- https://bugs.mageia.org/show_bug.cgi?id=26532

- http://www.squid-cache.org/Advisories/SQUID-2020_4.txt

- https://www.cve.org/CVERecord?id=CVE-2020-11945

Resolution

SRPMS

- 7/core/squid-4.11-1.mga7

Publication date: 05 May 2020
URL: https://advisories.mageia.org/MGASA-2020-0187.html
Type: security
CVE: CVE-2020-11945

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here