Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Date: Tue, 24 Jan 2017 16:11:06 -0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific LinuxFrom: Pat Riehecky Subject: Security ERRATA Moderate: squid34 on SL6.x i386/x86_64 MIME-Version: 1.0 Message-ID: <20170124161106.10136.44428@slpackages.fnal.gov> Synopsis: Moderate: squid34 security update Advisory ID: SLSA-2017:0183-1 Issue Date: 2017-01-24 CVE Numbers: CVE-2016-10002 -- Security Fix(es): * It was found that squid did not properly remove connection specific headers when answering conditional requests using a cached request. A remote attacker could send a specially crafted request to an HTTP server via the squid proxy and steal private data from other connections. (CVE-2016-10002) -- SL6 x86_64 squid34-3.4.14-9.el6_8.4.x86_64.rpm squid34-debuginfo-3.4.14-9.el6_8.4.x86_64.rpm i386 squid34-3.4.14-9.el6_8.4.i686.rpm squid34-debuginfo-3.4.14-9.el6_8.4.i686.rpm - Scientific Linux Development Team