[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*


oval:org.secpod.oval:def:63499
squid: Web proxy cache server - squid3: Web proxy cache server Several security issues were fixed in Squid.

oval:org.secpod.oval:def:1601140
An issue was discovered in Squid through 4.7. When handling the tag esi:when when ESI is enabled, Squid calls ESIExpression::Evaluate. This function uses a fixed stack buffer to hold the expression while it"s being evaluated. When processing the expression, it could either evaluate the top of the st ...

oval:org.secpod.oval:def:1801696
Affected versions: Squid 3.x -> 3.5.28, Squid 4.x -> 4.10 and Squid 5.x -> 5.0.1 Fixed in version: Squid 4.11 and 5.0.2Affected versions: Squid 3.x -> 3.5.28, Squid 4.x -> 4.10 and Squid 5.x -> 5.0.1 Fixed in version: Squid 4.11 and 5.0.2Affected versions: Squid 2.x -> 2.7.STABL ...

oval:org.secpod.oval:def:705468
squid: Web proxy cache server - squid3: Web proxy cache server Several security issues were fixed in Squid.

oval:org.secpod.oval:def:1701761
A flaw was found in Squid through version 4.7. When handling the tag esi:when, when ESI is enabled, Squid calls the ESIExpression::Evaluate function which uses a fixed stack buffer to hold the expression. While processing the expression, there is no check to ensure that the stack won't overflow. The ...

oval:org.secpod.oval:def:89000270
This update for squid to version 4.11 fixes the following issues: - CVE-2020-11945: Fixed a potential remote code execution vulnerability when using HTTP Digest Authentication . - CVE-2019-12519, CVE-2019-12521: Fixed incorrect buffer handling that can result in cache poisoning, remote execution, an ...

oval:org.secpod.oval:def:89000275
This update for squid fixes the following issues: - CVE-2019-12519, CVE-2019-12521: fixes incorrect buffer handling that can result in cache poisoning, remote execution, and denial of service attacks when processing ESI responses . - CVE-2020-11945: fixes a potential remote execution vulnerability w ...

oval:org.secpod.oval:def:89000472
This update for squid to version 4.11 fixes the following issues: - CVE-2020-11945: Fixed a potential remote code execution vulnerability when using HTTP Digest Authentication . - CVE-2019-12519, CVE-2019-12521: Fixed incorrect buffer handling that can result in cache poisoning, remote execution, an ...

oval:org.secpod.oval:def:604842
Multiple security issues were discovered in the Squid proxy caching server, which could result in the bypass of security filters, information disclosure, the execution of arbitrary code or denial of service.

oval:org.secpod.oval:def:63525
Multiple security issues were discovered in the Squid proxy caching server, which could result in the bypass of security filters, information disclosure, the execution of arbitrary code or denial of service.

oval:org.secpod.oval:def:89000262
This update for squid3 fixes the following issues: - Fixed a Cache Poisoning and Request Smuggling attack - Fixed incorrect buffer handling that can result in cache poisoning, remote execution, and denial of service attacks when processing ESI responses - Fixed handling of hostname in cachemgr.cgi ...

oval:org.secpod.oval:def:1505298
The advisory is missing the security advisory description. For more information please visit the reference link

oval:org.secpod.oval:def:504724
Squid is a high-performance proxy caching server for web clients, supporting FTP, Gopher, and HTTP data objects. The following packages have been upgraded to a later upstream version: squid . Security Fix: * squid: Improper input validation in request allows for proxy manipulation * squid: Off-by- ...

oval:org.secpod.oval:def:2500091
Squid is a high-performance proxy caching server for web clients, supporting FTP, Gopher, and HTTP data objects.

oval:org.secpod.oval:def:68001
Squid is a high-performance proxy caching server for web clients, supporting FTP, Gopher, and HTTP data objects. The following packages have been upgraded to a later upstream version: squid . Security Fix: * squid: Improper input validation in request allows for proxy manipulation * squid: Off-by- ...

CPE    4
cpe:/o:debian:debian_linux:9.0
cpe:/a:squid-cache:squid
cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~
cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~
...
CWE    1
CWE-787
*CVE
CVE-2019-12521

© SecPod Technologies