Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

openSUSE Leap 15.2: 2021:0879-1 Important: Squid Memory Leak Fix

opensuse
Calendar Grey June 16, 2021
Dist Opensuse Esm H88
A crucial patch release for squid on openSUSE addresses various concerns and incorporates solutions for several security flaws.
An update that solves 5 vulnerabilities and has three fixes is now available

Description

This update for squid fixes the following issues:

- update to 4.15:

- CVE-2021-28652: Broken cache manager URL parsing (bsc#1185918)

- CVE-2021-28651: Memory leak in RFC 2169 response parsing (bsc#1185921)

- CVE-2021-28662: Limit HeaderLookupTable_t::lookup() to BadHdr and

specific IDs (bsc#1185919)

- CVE-2021-31806: Handle more Range requests (bsc#1185916)

- CVE-2020-25097: HTTP Request Smuggling vulnerability (bsc#1183436)

- Handle more partial responses (bsc#1185923)

- fix previous change to reinstante permissions macros, because the wrong

path has been used (bsc#1171569).

- use libexecdir instead of libdir to conform to recent changes in Factory

(bsc#1171164).

- Reinstate permissions macros for pinger binary, because the permissions

package is also responsible for setting up the cap_net_raw capability,

currently a fresh squid install doesn't get a capability bit at all

(bsc#1171569).

- Change pinger and...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2021-879=1

Package List

- openSUSE Leap 15.2 (x86_64):

squid-4.15-lp152.2.9.1

squid-debuginfo-4.15-lp152.2.9.1

squid-debugsource-4.15-lp152.2.9.1

References

https://www.suse.com/security/cve/CVE-2020-25097.html

https://www.suse.com/security/cve/CVE-2021-28651.html

https://www.suse.com/security/cve/CVE-2021-28652.html

https://www.suse.com/security/cve/CVE-2021-28662.html

https://www.suse.com/security/cve/CVE-2021-31806.html

https://bugzilla.suse.com/1171164

https://bugzilla.suse.com/1171569

https://bugzilla.suse.com/1183436

https://bugzilla.suse.com/1185916

https://bugzilla.suse.com/1185918

https://bugzilla.suse.com/1185919

https://bugzilla.suse.com/1185921

https://bugzilla.suse.com/1185923

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2021:0879-1
Rating: important
Affected Products: openSUSE Leap 15.2 ble.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here