[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2020:4743-01 -- Redhat libecap, squid

ID: oval:org.secpod.oval:def:504724Date: (C)2020-12-23   (M)2024-05-09
Class: PATCHFamily: unix




Squid is a high-performance proxy caching server for web clients, supporting FTP, Gopher, and HTTP data objects. The following packages have been upgraded to a later upstream version: squid . Security Fix: * squid: Improper input validation in request allows for proxy manipulation * squid: Off-by-one error in addStackElement allows for heap buffer overflow and crash * squid: Improper input validation in URI processor * squid: Improper access restriction in url_regex may lead to security bypass * squid: Heap overflow issue in URN processing * squid: Information Disclosure issue in FTP Gateway * squid: Out of bounds read in Proxy-Authorization header causes DoS * squid: Denial of service in cachemgr.cgi * squid: Buffer overflow in URI processor * squid: Cross-Site Request Forgery issue in HTTP Request processing * squid: HTTP Request Splitting issue in HTTP message processing * squid: Information Disclosure issue in HTTP Digest Authentication * squid: Mishandled HTML in the host parameter to cachemgr.cgi results in insecure behaviour * squid: Improper input validation issues in HTTP Request processing * squid: Buffer overflow in reverse-proxy configurations * squid: DoS in TLS handshake * squid: Request smuggling and poisoning attack against the HTTP cache * squid: Improper input validation could result in a DoS For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.3 Release Notes linked from the References section.

Platform:
Red Hat Enterprise Linux 8
Product:
libecap
squid
Reference:
RHSA-2020:4743-01
CVE-2019-12520
CVE-2019-12521
CVE-2019-12523
CVE-2019-12524
CVE-2019-12526
CVE-2019-12528
CVE-2019-12529
CVE-2019-12854
CVE-2019-18676
CVE-2019-18677
CVE-2019-18678
CVE-2019-18679
CVE-2019-18860
CVE-2020-8449
CVE-2020-8450
CVE-2020-14058
CVE-2020-15049
CVE-2020-24606
CVE    18
CVE-2020-14058
CVE-2020-15049
CVE-2020-24606
CVE-2020-8449
...
CPE    3
cpe:/a:kali:libecap
cpe:/o:redhat:enterprise_linux:8
cpe:/a:squid-cache:squid

© SecPod Technologies