Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a . MGASA-2024-0102 - Updated squid packages fix security vulnerabilities Publication date: 31 Mar 2024 URL: https://advisories.mageia.org/MGASA-2024-0102.html Type: security Affected Mageia releases: 9 CVE: CVE-2023-46724, CVE-2023-49285, CVE-2023-49286, CVE-2023-50269, CVE-2024-23638, CVE-2024-25111, CVE-2024-25617 Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a specially crafted SSL Certificate in a server certificate chain. This attack is limited to HTTPS and SSL-Bump. (CVE-2023-46724) Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Message processing. (CVE-2023-49285) Due to an Incorrect Check of Function Return Value bug Squid is vulnerable to a Denial of Service attack against its Helper process management. (CVE-2023-49286) Due to an Uncontrolled Recursion bug in versions 2.6 through 2.7.STABLE9, versions 3.1 through 5.9, and versions 6.0.1 through 6.5, Squid may be vulnerable to a Denial of Service attack against HTTP Request parsing. This problem allows a remote client to perform Denial of Service attack by sending a large X-Forwarded-For header when the follow_x_forwarded_for feature is configured. (CVE-2023-50269) Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial of Service attack against Cache Manager error responses. This problem allows atrusted client to perform Denial of Service when generating error pages for Client Manager reports. (CVE-2024-23638) Starting in version 3.5.27 and prior to version 6.8, Squid may be vulnerable to a Denial of Service attack against HTTP Chunked decoder due to an uncontrolled recursion bug. This problem allows a remote attacker to cause Denial of Service when sending a crafted, chunked, encoded HTTP Message. (CVE-2024-25111) Due to a Collapse of Data into Unsafe Value bug ,Squid may be vulnerable to a Denial of Service attack against HTTP header parsing. This problem allows a remote client or a remote server to perform Denial of Service when sending oversized headers in HTTP messages. In versions of Squid prior to 6.5 this can be achieved if the request_header_max_size or reply_header_max_size settings are unchanged from the default. (CVE-2024-25617) References: - https://bugs.mageia.org/show_bug.cgi?id=33003 - - https://lists.debian.org/debian-security-announce/2024/msg00043.html - https://www.cve.org/CVERecord?id=CVE-2023-46724 - https://www.cve.org/CVERecord?id=CVE-2023-49285 - https://www.cve.org/CVERecord?id=CVE-2023-49286 - https://www.cve.org/CVERecord?id=CVE-2023-50269 - https://www.cve.org/CVERecord?id=CVE-2024-23638 - https://www.cve.org/CVERecord?id=CVE-2024-25111 - https://www.cve.org/CVERecord?id=CVE-2024-25617 SRPMS: - 9/core/squid-5.9-1.2.mga9 . Recent updates to Squid packages have addressed several security vulnerabilities that may impact Mageia systems. It's essential to review the listed CVEs for possible risks. Squid Update, Mageia Security, Denial of Service, Software Vulnerabilities. . Severity: Critical. LinuxSecurity.com Team
Updated node.js packages that fix one security issue are now available for Red Hat OpenShift Enterprise 2.1. Red Hat Product Security has rated this update as having Important security impact. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: node.js security update Advisory ID: RHSA-2015:1545-01 Product: Red Hat OpenShift Enterprise Advisory URL: https://access.redhat.com/errata/RHSA-2015:1545.html Issue date: 2015-08-04 CVE Names: CVE-2014-3566 ==================================================================== 1. Summary: Updated node.js packages that fix one security issue are now available for Red Hat OpenShift Enterprise 2.1. Red Hat Product Security has rated this update as having Important security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: RHOSE Node 2.1 - noarch 3. Description: OpenShift Enterprise by Red Hat is the company's cloud computing Platform-as-a-Service (PaaS) solution designed for on-premise or private cloud deployments. Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. A flaw was found in the way SSL 3.0 handled padding bytes when decrypting messages encrypted using block ciphers in cipher block chaining (CBC) mode. This flaw allows a man-in-the-middle (MITM) attacker to decrypt a selected byte of a cipher text in as few as 256 tries if they are able to force a victim application to repeatedly send the same data over newly created SSL 3.0 connections. (CVE-2014-3566) All OpenShift Enterprise users are advised to upgrade to these updated packages, which correct this issue. 4. Solution: Before applyingthis update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1152789 - CVE-2014-3566 SSL/TLS: Padding Oracle On Downgraded Legacy Encryption attack 6. Package List: RHOSE Node 2.1: Source: openshift-origin-node-proxy-1.22.3.4-1.el6op.src.rpm noarch: openshift-origin-node-proxy-1.22.3.4-1.el6op.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2014-3566 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2015 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFVwPPrXlSAg2UNWIIRAicFAJwLtBa83jvknJ4O1bikpq+xg4A14QCfVl7R U5g35mQX0vIx8VGzFhtrO3g=e7zz -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
It was discovered that OpenLDAP did not correctly handle SSL certificates with zero bytes in the Common Name. A remote attacker could exploit this to perform a man in the middle attack to view sensitive information or alter encrypted communications. [More...]. ==========================================================Ubuntu Security Notice USN-858-1 November 12, 2009 openldap2.2 vulnerability CVE-2009-3767 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: libldap-2.2-7 2.2.26-5ubuntu2.9 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: It was discovered that OpenLDAP did not correctly handle SSL certificates with zero bytes in the Common Name. A remote attacker could exploit this to perform a man in the middle attack to view sensitive information or alter encrypted communications. Updated packages for Ubuntu 6.06 LTS: Source archives: Size/MD5: 516098 098a03b4f7d511ce730e9647deca2072 Size/MD5: 1028 5a95dae94a1016fbcf41c1c1992ea8e6 Size/MD5: 2626629 afc8700b5738da863b30208e1d3e9de8 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 130854 1f1b40b12adcb557a810194d0c4f7993 Size/MD5: 166444 500528d10502361c075a08578c1586f5 Size/MD5: 961974 f56eef919306d6ca7f4a7a090d2ae6ba i386 architecture (x86 compatible Intel/AMD): Size/MD5: 118638 0558a833fb6eadf4d87bd9fd6e687838 Size/MD5: 146444 fc85d5259c97622324047bbda153937d Size/MD5: 873424 358c78f76ee16010c1fb81e89adfe849 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 13301292d9de435a795261e6bf4143f2bf59c7 Size/MD5: 157480 099b1ee5e158f77be109a7972587f596 Size/MD5: 960052 850fb56995224edd6ae329af1b8236ef sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 120932 4fa0f7accd968ba71dff1f7c5b2ef811 Size/MD5: 148546 2d1af209a8b53a8315fbd4bd86573d70 Size/MD5: 903928 4aa6b0478821e803c80a020b031aafed . Recent OpenLDAP flaw exposes systems to remote threats targeting SSL vulnerabilities for data theft. Ensure your Ubuntu is updated immediately!. OpenLDAP Exploitation, SSL Security Threat, Ubuntu Update, Remote Attack. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.