Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

SUSE Linux Enterprise Server 12-SP5: Critical Squid Vulnerability Advisory

suse
Calendar Grey September 2, 2020
Dist Suse Esm H88
Important SUSE Security Patch for Squid resolves various security flaws impacting SUSE Linux Enterprise Server.
An update that fixes four vulnerabilities is now available

Summary

This update for squid fixes the following issues: squid was updated to version 4.13: - CVE-2020-24606: Fix livelocking in peerDigestHandleReply (bsc#1175671). - CVE-2020-15811: Improve Transfer-Encoding handling (bsc#1175665). - CVE-2020-15810: Enforce token characters for field-name (bsc#1175664). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2020-2443=1 Package List: - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): squid-4.13-4.15.1 squid-debuginfo-4.13-4.15.1 squid-debugsource-4.13-4.15.1

References

#1173455 #1175664 #1175665 #1175671

Cross- CVE-2020-15049 CVE-2020-15810 CVE-2020-15811

CVE-2020-24606

Affected Products:

SUSE Linux Enterprise Server 12-SP5

https://www.suse.com/security/cve/CVE-2020-15049.html

https://www.suse.com/security/cve/CVE-2020-15810.html

https://www.suse.com/security/cve/CVE-2020-15811.html

https://www.suse.com/security/cve/CVE-2020-24606.html

https://bugzilla.suse.com/1173455

https://bugzilla.suse.com/1175664

https://bugzilla.suse.com/1175665

https://bugzilla.suse.com/1175671

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:2443-1
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here