[ALAS-2014-433] Amazon Linux AMI 2014.03 - ALAS-2014-433: important priority package update for squid

Severity Important
Affected Packages 4
CVEs 3

Package updates are available for Amazon Linux AMI that fix the following vulnerabilities:
CVE-2014-3609:
A flaw was found in the way Squid handled malformed HTTP Range headers. A remote attacker able to send HTTP requests to the Squid proxy could use this flaw to crash Squid.

CVE-2014-0128:
A denial of service flaw was found in the way Squid processed certain HTTPS requests when the SSL Bump feature was enabled. A remote attacker could send specially crafted requests that could cause Squid to crash.

CVE-2013-4115:
A buffer overflow flaw was found in Squid's DNS lookup module. A remote attacker able to send HTTP requests to the Squid proxy could use this flaw to crash Squid.

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/amazonlinux/squid?arch=x86_64&distro=amazonlinux-1 amazonlinux squid < 3.1.10-29.17.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/squid?arch=i686&distro=amazonlinux-1 amazonlinux squid < 3.1.10-29.17.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/squid-debuginfo?arch=x86_64&distro=amazonlinux-1 amazonlinux squid-debuginfo < 3.1.10-29.17.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/squid-debuginfo?arch=i686&distro=amazonlinux-1 amazonlinux squid-debuginfo < 3.1.10-29.17.amzn1 amazonlinux-1 i686
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...