[ALAS2-2023-1907] Amazon Linux 2 2017.12 - ALAS2-2023-1907: important priority package update for squid

Severity Important
Affected Packages 12
CVEs 2

Package updates are available for Amazon Linux 2 that fix the following vulnerabilities:
CVE-2022-41318:
A flaw was found in Squid. An incorrect integer overflow protection in the Squid SSPI and SMB authentication helpers is vulnerable to a buffer overflow attack, resulting in information disclosure or a denial of service.

CVE-2021-46784:
In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due to improper buffer management, a Denial of Service can occur when processing long Gopher server responses.

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/amazonlinux/squid?arch=x86_64&distro=amazonlinux-2 amazonlinux squid < 3.5.20-17.amzn2.7.1 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/squid?arch=i686&distro=amazonlinux-2 amazonlinux squid < 3.5.20-17.amzn2.7.1 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/squid?arch=aarch64&distro=amazonlinux-2 amazonlinux squid < 3.5.20-17.amzn2.7.1 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/squid-sysvinit?arch=x86_64&distro=amazonlinux-2 amazonlinux squid-sysvinit < 3.5.20-17.amzn2.7.1 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/squid-sysvinit?arch=i686&distro=amazonlinux-2 amazonlinux squid-sysvinit < 3.5.20-17.amzn2.7.1 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/squid-sysvinit?arch=aarch64&distro=amazonlinux-2 amazonlinux squid-sysvinit < 3.5.20-17.amzn2.7.1 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/squid-migration-script?arch=x86_64&distro=amazonlinux-2 amazonlinux squid-migration-script < 3.5.20-17.amzn2.7.1 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/squid-migration-script?arch=i686&distro=amazonlinux-2 amazonlinux squid-migration-script < 3.5.20-17.amzn2.7.1 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/squid-migration-script?arch=aarch64&distro=amazonlinux-2 amazonlinux squid-migration-script < 3.5.20-17.amzn2.7.1 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/squid-debuginfo?arch=x86_64&distro=amazonlinux-2 amazonlinux squid-debuginfo < 3.5.20-17.amzn2.7.1 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/squid-debuginfo?arch=i686&distro=amazonlinux-2 amazonlinux squid-debuginfo < 3.5.20-17.amzn2.7.1 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/squid-debuginfo?arch=aarch64&distro=amazonlinux-2 amazonlinux squid-debuginfo < 3.5.20-17.amzn2.7.1 amazonlinux-2 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...