Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: 2020:14460-1 Important: Squid3 Denial Of Service and Code Execution

suse
Calendar Grey August 24, 2020
Dist Suse Esm H88
SUSE Security Patch for nginx addressing critical vulnerabilities to enhance system integrity and reliability.
An update that fixes 21 vulnerabilities is now available

Summary

This update for squid3 fixes the following issues: - Fixed a Cache Poisoning and Request Smuggling attack (CVE-2020-15049, bsc#1173455) - Fixed incorrect buffer handling that can result in cache poisoning, remote execution, and denial of service attacks when processing ESI responses (CVE-2019-12519, CVE-2019-12521, bsc#1169659) - Fixed handling of hostname in cachemgr.cgi (CVE-2019-18860, bsc#1167373) - Fixed a potential remote execution vulnerability when using HTTP Digest Authentication (CVE-2020-11945, bsc#1170313) - Fixed a potential ACL bypass, cache-bypass and cross-site scripting attack when processing invalid HTTP Request messages (CVE-2019-12520, CVE-2019-12524, bsc#1170423) - Fixed a potential denial of service when processing TLS certificates

References

#1140738 #1141329 #1141332 #1156323 #1156324

#1156326 #1156328 #1156329 #1162687 #1162689

#1162691 #1167373 #1169659 #1170313 #1170423

#1173304 #1173455

Cross- CVE-2019-12519 CVE-2019-12520 CVE-2019-12521

CVE-2019-12523 CVE-2019-12524 CVE-2019-12525

CVE-2019-12526 CVE-2019-12528 CVE-2019-12529

CVE-2019-13345 CVE-2019-18676 CVE-2019-18677

CVE-2019-18678 CVE-2019-18679 CVE-2019-18860

CVE-2020-11945 CVE-2020-14059 CVE-2020-15049

CVE-2020-8449 CVE-2020-8450 CVE-2020-8517

Affected Products:

SUSE Linux Enterprise Server 11-SP4-LTSS

SUSE Linux Enterprise Point of Sale 11-SP3

SUSE Linux Enterprise Debuginfo 11-SP4

https://www.suse.com/security/cve/CVE-2019-12519.html

https://www.suse.com/security/cve/CVE-2019-12520.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:14460-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here