An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for squid3 ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:14914-1 Rating: important References: #1183436 #1185921 Cross-References: CVE-2020-25097 CVE-2021-28651 CVSS scores: CVE-2020-25097 (NVD) : 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N CVE-2020-25097 (SUSE): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N CVE-2021-28651 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-28651 (SUSE): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H Affected Products: SUSE Linux Enterprise Debuginfo 11-SP4 SUSE Linux Enterprise Point of Sale 11-SP3 SUSE Linux Enterprise Server 11-SP4-LTSS ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for squid3 fixes the following issues: - CVE-2021-28651: Fixed a denial of service issue when processing URN resource identifiers (bsc#1185921). - CVE-2020-25097: Fixed an HTTP request smuggling issue (bsc#1183436). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP4-LTSS: zypper in -t patch slessp4-squid3-14914=1 - SUSE Linux Enterprise Point of Sale 11-SP3: zypper in -t patch sleposp3-squid3-14914=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-squid3-14914=1 Package List: - SUSE Linux Enterprise Server 11-SP4-LTSS (i586 ppc64 s390x x86_64): squid3-3.1.23-8.16.37.18.1 - SUSE Linux Enterprise Point of Sale 11-SP3 (i586): squid3-3.1.23-8.16.37.18.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ppc64 s390x x86_64): squid3-debuginfo-3.1.23-8.16.37.18.1 squid3-debugsource-3.1.23-8.16.37.18.1 References: https://www.suse.com/security/cve/CVE-2020-25097.html https://www.suse.com/security/cve/CVE-2021-28651.html https://bugzilla.suse.com/1183436 https://bugzilla.suse.com/1185921 . SUSE unveils significant patch for squid3 targeting two severe vulnerabilities that threaten server stability and security.. SUSE Update,squid3 Security Fixes,Denial of Service,HTTP Request Smuggling. . Severity: Important. LinuxSecurity.com Team
Due to improper input validation, Squid is vulnerable to an HTTP Request Smuggling attack. This problem allows a trusted client to perform HTTP Request . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2598-1
An update that fixes three vulnerabilities is now available. . SUSE Security Update: Security update for squid3 ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:14590-1 Rating: critical References: #1175664 #1175665 #1175671 Cross-References: CVE-2020-15810 CVE-2020-15811 CVE-2020-24606 Affected Products: SUSE Linux Enterprise Server 11-SP4-LTSS SUSE Linux Enterprise Point of Sale 11-SP3 SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for squid3 fixes the following issues: - CVE-2020-15811: Fixed an HTTP request splitting vulnerability (bsc#1175665). - CVE-2020-24606: Fixed a DoS vulnerability when processing Cache Digest Responses (bsc#1175671). - CVE-2020-15810: Fixed an HTTP request smuggling vulnerability (bsc#1175664). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP4-LTSS: zypper in -t patch slessp4-squid3-14590=1 - SUSE Linux Enterprise Point of Sale 11-SP3: zypper in -t patch sleposp3-squid3-14590=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-squid3-14590=1 Package List: - SUSE Linux Enterprise Server 11-SP4-LTSS (i586 ppc64 s390x x86_64): squid3-3.1.23-8.16.37.15.1 - SUSE Linux Enterprise Point of Sale 11-SP3 (i586): squid3-3.1.23-8.16.37.15.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ppc64 s390x x86_64): squid3-debuginfo-3.1.23-8.16.37.15.1 squid3-debugsource-3.1.23-8.16.37.15.1 References: https://www.suse.com/security/cve/CVE-2020-15810.html https://www.suse.com/security/cve/CVE-2020-15811.html https://www.suse.com/security/cve/CVE-2020-24606.html https://bugzilla.suse.com/1175664 https://bugzilla.suse.com/1175665 https://bugzilla.suse.com/1175671 . The latest squid3 patch addresses three major vulnerabilities, which involve potential denial-of-service attacks and request smuggling risks.. SUSE Security Update,squid3 update,HTTP issues,security patches. . Severity: Critical. LinuxSecurity.com Team
The update of squid3 released as DLA-2278-2 introduced a regression due to the updated fix for CVE-2019-12529. The new Kerberos authentication code prevented base64 token negotiation. Updated squid3 packages are now . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2278-3
An update that fixes 21 vulnerabilities is now available. . SUSE Security Update: Security update for squid3 ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:14460-1 Rating: important References: #1140738 #1141329 #1141332 #1156323 #1156324 #1156326 #1156328 #1156329 #1162687 #1162689 #1162691 #1167373 #1169659 #1170313 #1170423 #1173304 #1173455 Cross-References: CVE-2019-12519 CVE-2019-12520 CVE-2019-12521 CVE-2019-12523 CVE-2019-12524 CVE-2019-12525 CVE-2019-12526 CVE-2019-12528 CVE-2019-12529 CVE-2019-13345 CVE-2019-18676 CVE-2019-18677 CVE-2019-18678 CVE-2019-18679 CVE-2019-18860 CVE-2020-11945 CVE-2020-14059 CVE-2020-15049 CVE-2020-8449 CVE-2020-8450 CVE-2020-8517 Affected Products: SUSE Linux Enterprise Server 11-SP4-LTSS SUSE Linux Enterprise Point of Sale 11-SP3 SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that fixes 21 vulnerabilities is now available. Description: This update for squid3 fixes the following issues: - Fixed a Cache Poisoning and Request Smuggling attack (CVE-2020-15049, bsc#1173455) - Fixed incorrect buffer handling that can result in cache poisoning, remote execution, and denial of service attacks when processing ESI responses (CVE-2019-12519, CVE-2019-12521, bsc#1169659) - Fixed handling of hostname in cachemgr.cgi (CVE-2019-18860, bsc#1167373) - Fixed a potential remote execution vulnerability when using HTTP Digest Authentication (CVE-2020-11945, bsc#1170313) - Fixed a potential ACL bypass, cache-bypass and cross-site scripting attack when processing invalid HTTP Request messages (CVE-2019-12520, CVE-2019-12524, bsc#1170423) - Fixed a potential denial of service when processing TLS certificates during HTTPS connections (CVE-2020-14059, bsc#1173304) - Fixed a potential denial of service associated with incorrect buffer management of HTTP Basic Authentication credentials (bsc#1141329, CVE-2019-12529) - Fixed an incorrect buffer management resulting in vulnerability to a denial of service during processing of HTTP Digest Authentication credentials (bsc#1141332, CVE-2019-12525) - Fix XSS via user_name or auth parameter in cachemgr.cgi (bsc#1140738, CVE-2019-13345) - Fixed a potential code execution vulnerability (CVE-2019-12526, bsc#1156326) - Fixed HTTP Request Splitting in HTTP message processing and information disclosure in HTTP Digest Authentication (CVE-2019-18678, CVE-2019-18679, bsc#1156323, bsc#1156324) - Fixed a security issue allowing a remote client ability to cause use a buffer overflow when squid is acting as reverse-proxy. (CVE-2020-8449, CVE-2020-8450, bsc#1162687) - Fixed a security issue allowing for information disclosure in FTP gateway (CVE-2019-12528, bsc#1162689) - Fixed a security issue in ext_lm_group_acl when processing NTLM Authentication credentials. (CVE-2020-8517, bsc#1162691) - Fixed Cross-Site Request Forgery in HTTP Request processing (CVE-2019-18677, bsc#1156328) - Disable urn parsing and parsing of unknown schemes (bsc#1156329, CVE-2019-12523, CVE-2019-18676) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP4-LTSS: zypper in -t patch slessp4-squid3-14460=1 - SUSE Linux Enterprise Point of Sale 11-SP3: zypper in -t patch sleposp3-squid3-14460=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patchdbgsp4-squid3-14460=1 Package List: - SUSE Linux Enterprise Server 11-SP4-LTSS (i586 ppc64 s390x x86_64): squid3-3.1.23-8.16.37.12.1 - SUSE Linux Enterprise Point of Sale 11-SP3 (i586): squid3-3.1.23-8.16.37.12.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ppc64 s390x x86_64): squid3-debuginfo-3.1.23-8.16.37.12.1 squid3-debugsource-3.1.23-8.16.37.12.1 References: https://www.suse.com/security/cve/CVE-2019-12519.html https://www.suse.com/security/cve/CVE-2019-12520.html https://www.suse.com/security/cve/CVE-2019-12521.html https://www.suse.com/security/cve/CVE-2019-12523.html https://www.suse.com/security/cve/CVE-2019-12524.html https://www.suse.com/security/cve/CVE-2019-12525.html https://www.suse.com/security/cve/CVE-2019-12526.html https://www.suse.com/security/cve/CVE-2019-12528.html https://www.suse.com/security/cve/CVE-2019-12529.html https://www.suse.com/security/cve/CVE-2019-13345.html https://www.suse.com/security/cve/CVE-2019-18676.html https://www.suse.com/security/cve/CVE-2019-18677.html https://www.suse.com/security/cve/CVE-2019-18678.html https://www.suse.com/security/cve/CVE-2019-18679.html https://www.suse.com/security/cve/CVE-2019-18860.html https://www.suse.com/security/cve/CVE-2020-11945.html https://www.suse.com/security/cve/CVE-2020-14059.html https://www.suse.com/security/cve/CVE-2020-15049.html https://www.suse.com/security/cve/CVE-2020-8449.html https://www.suse.com/security/cve/CVE-2020-8450.html https://www.suse.com/security/cve/CVE-2020-8517.html https://bugzilla.suse.com/1140738 https://bugzilla.suse.com/1141329 https://bugzilla.suse.com/1141332 https://bugzilla.suse.com/1156323 https://bugzilla.suse.com/1156324 https://bugzilla.suse.com/1156326 https://bugzilla.suse.com/1156328 https://bugzilla.suse.com/1156329 https://bugzilla.suse.com/1162687 https://bugzilla.suse.com/1162689 https://bugzilla.suse.com/1162691 https://bugzilla.suse.com/1167373 https://bugzilla.suse.com/1169659 https://bugzilla.suse.com/1170313 https://bugzilla.suse.com/1170423 https://bugzilla.suse.com/1173304 https://bugzilla.suse.com/1173455 _______________________________________________ sle-security-updates mailing list
The update of squid3 released as DLA-2278-1 contained an incomplete fix for CVE-2019-12523 that prevented services which rely on the icap or ecap protocol to function properly. Updated squid3 packages are now available to correct this issue. . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2278-2
It was discovered that the IPv6 support code in Squid does not properly handle certain DNS responses, resulting in deallocation of an invalid pointer and a daemon crash. . -----BEGIN PGP SIGNED MESSAGE-----Hash: SHA1 - -------------------------------------------------------------------------Debian Security Advisory DSA-2381-1
It was found that Squid, a high-performance proxy caching server for web clients, has been affected by the following security vulnerabilities. . Package : squid3 Version : 3.4.8-6+deb8u9 CVE ID : CVE-2019-12526 CVE-2019-18677 CVE-2019-18678 CVE-2019-18679 It was found that Squid, a high-performance proxy caching server for web clients, has been affected by the following security vulnerabilities. CVE-2019-12526 URN response handling in Squid suffers from a heap-based buffer overflow. When receiving data from a remote server in response to an URN request, Squid fails to ensure that the response can fit within the buffer. This leads to attacker controlled data overflowing in the heap. CVE-2019-18677 When the append_domain setting is used (because the appended characters do not properly interact with hostname length restrictions), it can inappropriately redirect traffic to origins it should not be delivered to. This happens because of incorrect message processing. CVE-2019-18678 A programming error allows attackers to smuggle HTTP requests through frontend software to a Squid instance that splits the HTTP Request pipeline differently. The resulting Response messages corrupt caches (between a client and Squid) with attacker-controlled content at arbitrary URLs. Effects are isolated to software between the attacker client and Squid. There are no effects on Squid itself, nor on any upstream servers. The issue is related to a request header containing whitespace between a header name and a colon. CVE-2019-18679 Due to incorrect data management, Squid is vulnerable to information disclosure when processing HTTP Digest Authentication. Nonce tokens contain the raw byte value of a pointer that sits within heap memory allocation. This information reduces ASLR protections and may aid attackers isolating memory areas to target for remote code executionattacks. For Debian 8 "Jessie", these problems have been fixed in version 3.4.8-6+deb8u9. We recommend that you upgrade your squid3 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . This advisory alerts users of Debian 8 to multiple vulnerabilities in the Squid3 package that may risk unauthorized access and data leakage. Squid3 Security, Debian LTS Advisory, Proxy Caching Vulnerabilities, HTTP Request Smuggling. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.