Updated squid packages fix security vulnerability: Due to an integer overflow bug Squid is vulnerable to credential replay and remote code execution attacks against HTTP Digest Authentication tokens. When memory pooling is used this problem allows a remote client to replay a . MGASA-2020-0187 - Updated squid packages fix security vulnerability Publication date: 05 May 2020 URL: https://advisories.mageia.org/MGASA-2020-0187.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-11945 Updated squid packages fix security vulnerability: Due to an integer overflow bug Squid is vulnerable to credential replay and remote code execution attacks against HTTP Digest Authentication tokens. When memory pooling is used this problem allows a remote client to replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. When memory pooling is disabled this problem allows a remote client to perform remote code execution through the free'd nonce credentials (CVE-2020-11945). References: - https://bugs.mageia.org/show_bug.cgi?id=26532 - http://www.squid-cache.org/Advisories/SQUID-2020_4.txt - https://www.cve.org/CVERecord?id=CVE-2020-11945 SRPMS: - 7/core/squid-4.11-1.mga7 . Recent squid updates for Mageia address significant security vulnerabilities that could lead to remote code execution and the possibility of replay attacks on credentials.. Squid, Remote Code Execution, Credential Replay, Mageia Security. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.