This update for squid3 fixes the following issues: - Fixed a Cache Poisoning and Request Smuggling attack (CVE-2020-15049, bsc#1173455) - Fixed incorrect buffer handling that can result in cache poisoning, remote execution, and denial of service attacks when processing ESI responses (CVE-2019-12519, CVE-2019-12521, bsc#1169659) - Fixed handling of hostname in cachemgr.cgi (CVE-2019-18860, bsc#1167373) - Fixed a potential remote execution vulnerability when using HTTP Digest Authentication (CVE-2020-11945, bsc#1170313) - Fixed a potential ACL bypass, cache-bypass and cross-site scripting attack when processing invalid HTTP Request messages (CVE-2019-12520, CVE-2019-12524, bsc#1170423) - Fixed a potential denial of service when processing TLS certificates
#1140738 #1141329 #1141332 #1156323 #1156324
#1156326 #1156328 #1156329 #1162687 #1162689
#1162691 #1167373 #1169659 #1170313 #1170423
#1173304 #1173455
Cross- CVE-2019-12519 CVE-2019-12520 CVE-2019-12521
CVE-2019-12523 CVE-2019-12524 CVE-2019-12525
CVE-2019-12526 CVE-2019-12528 CVE-2019-12529
CVE-2019-13345 CVE-2019-18676 CVE-2019-18677
CVE-2019-18678 CVE-2019-18679 CVE-2019-18860
CVE-2020-11945 CVE-2020-14059 CVE-2020-15049
CVE-2020-8449 CVE-2020-8450 CVE-2020-8517
Affected Products:
SUSE Linux Enterprise Server 11-SP4-LTSS
SUSE Linux Enterprise Point of Sale 11-SP3
SUSE Linux Enterprise Debuginfo 11-SP4
https://www.suse.com/security/cve/CVE-2019-12519.html
https://www.suse.com/security/cve/CVE-2019-12520.html
Get the latest Linux and open source security news straight to your inbox.