MGASA-2021-0499 - Updated squid packages fix security vulnerability

Publication date: 31 Oct 2021
URL: https://advisories.mageia.org/MGASA-2021-0499.html
Type: security
Affected Mageia releases: 8
CVE: CVE-2021-28116

Updated squid packages fix security vulnerability:

Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows
information disclosure because of an out-of-bounds read in WCCP protocol
data. This can be leveraged as part of a chain for remote code execution
as nobody (CVE-2021-28116).

Squid is updated to 4.17 that fixes this issue and other bugs.

References:
- https://bugs.mageia.org/show_bug.cgi?id=29524
- https://github.com/squid-cache/squid/security/advisories/GHSA-rgf3-9v3p-qp82
- https://github.com/squid-cache/squid/commit/3896e584d7eeb321d7becbcedec872ffa868dd87
- https://github.com/squid-cache/squid/commit/874e8b4ca0342a1c399ddadc1cf6998590fa46a6
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28116

SRPMS:
- 8/core/squid-4.17-1.mga8