Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Mageia 8: 2021-0499 Moderate: Squid Threat of Remote Execution

mageia
Calendar Grey October 31, 2021
Dist Mageia Esm H88
Mageia security notice for squid revision addresses severe information disclosure and potential remote execution threats.
Updated squid packages fix security vulnerability: Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure because of an out-of-bounds read...

Summary

Updated squid packages fix security vulnerability:
Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure because of an out-of-bounds read in WCCP protocol data. This can be leveraged as part of a chain for remote code execution as nobody (CVE-2021-28116).
Squid is updated to 4.17 that fixes this issue and other bugs.

References

- https://bugs.mageia.org/show_bug.cgi?id=29524

- https://github.com/squid-cache/squid/security/advisories/GHSA-rgf3-9v3p-qp82

- https://github.com/squid-cache/squid/commit/3896e584d7eeb321d7becbcedec872ffa868dd87

- https://github.com/squid-cache/squid/commit/874e8b4ca0342a1c399ddadc1cf6998590fa46a6

- https://www.cve.org/CVERecord?id=CVE-2021-28116

Resolution

SRPMS

- 8/core/squid-4.17-1.mga8

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 31 Oct 2021
URL: https://advisories.mageia.org/MGASA-2021-0499.html
Type: security
CVE: CVE-2021-28116

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here