[openSUSE-SU-2019:2541-1] Security update for squid

Severity Important
Affected Packages 1
CVEs 12

Security update for squid

This update for squid to version 4.9 fixes the following issues:

Security issues fixed:

  • CVE-2019-13345: Fixed multiple cross-site scripting vulnerabilities in cachemgr.cgi (bsc#1140738).
  • CVE-2019-12526: Fixed potential remote code execution during URN processing (bsc#1156326).
  • CVE-2019-12523,CVE-2019-18676: Fixed multiple improper validations in URI processing (bsc#1156329).
  • CVE-2019-18677: Fixed Cross-Site Request Forgery in HTTP Request processing (bsc#1156328).
  • CVE-2019-18678: Fixed incorrect message parsing which could have led to HTTP request splitting issue (bsc#1156323).
  • CVE-2019-18679: Fixed information disclosure when processing HTTP Digest Authentication (bsc#1156324).

Other issues addressed:

  • Fixed DNS failures when peer name was configured with any upper case characters
  • Fixed several rock cache_dir corruption issues

This update was imported from the SUSE:SLE-15:Update update project.

Package Affected Version
pkg:rpm/opensuse/squid?arch=x86_64&distro=opensuse-leap-15.1 < 4.9-lp151.2.7.1
Source # ID Name URL
Suse SUSE ratings https://www.suse.com/support/security/rating/
Suse URL of this CSAF notice https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2019_2541-1.json
Suse URL for openSUSE-SU-2019:2541-1 https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2PLGSQEPKZX62EREA7UHDNEMHR3Z23A6/#2PLGSQEPKZX62EREA7UHDNEMHR3Z23A6
Suse E-Mail link for openSUSE-SU-2019:2541-1 https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2PLGSQEPKZX62EREA7UHDNEMHR3Z23A6/#2PLGSQEPKZX62EREA7UHDNEMHR3Z23A6
Bugzilla SUSE Bug 1133089 https://bugzilla.suse.com/1133089
Bugzilla SUSE Bug 1140738 https://bugzilla.suse.com/1140738
Bugzilla SUSE Bug 1141329 https://bugzilla.suse.com/1141329
Bugzilla SUSE Bug 1141330 https://bugzilla.suse.com/1141330
Bugzilla SUSE Bug 1141332 https://bugzilla.suse.com/1141332
Bugzilla SUSE Bug 1141442 https://bugzilla.suse.com/1141442
Bugzilla SUSE Bug 1156323 https://bugzilla.suse.com/1156323
Bugzilla SUSE Bug 1156324 https://bugzilla.suse.com/1156324
Bugzilla SUSE Bug 1156326 https://bugzilla.suse.com/1156326
Bugzilla SUSE Bug 1156328 https://bugzilla.suse.com/1156328
Bugzilla SUSE Bug 1156329 https://bugzilla.suse.com/1156329
CVE SUSE CVE CVE-2019-12523 page https://www.suse.com/security/cve/CVE-2019-12523/
CVE SUSE CVE CVE-2019-12525 page https://www.suse.com/security/cve/CVE-2019-12525/
CVE SUSE CVE CVE-2019-12526 page https://www.suse.com/security/cve/CVE-2019-12526/
CVE SUSE CVE CVE-2019-12527 page https://www.suse.com/security/cve/CVE-2019-12527/
CVE SUSE CVE CVE-2019-12529 page https://www.suse.com/security/cve/CVE-2019-12529/
CVE SUSE CVE CVE-2019-12854 page https://www.suse.com/security/cve/CVE-2019-12854/
CVE SUSE CVE CVE-2019-13345 page https://www.suse.com/security/cve/CVE-2019-13345/
CVE SUSE CVE CVE-2019-18676 page https://www.suse.com/security/cve/CVE-2019-18676/
CVE SUSE CVE CVE-2019-18677 page https://www.suse.com/security/cve/CVE-2019-18677/
CVE SUSE CVE CVE-2019-18678 page https://www.suse.com/security/cve/CVE-2019-18678/
CVE SUSE CVE CVE-2019-18679 page https://www.suse.com/security/cve/CVE-2019-18679/
CVE SUSE CVE CVE-2019-3688 page https://www.suse.com/security/cve/CVE-2019-3688/
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/opensuse/squid?arch=x86_64&distro=opensuse-leap-15.1 opensuse squid < 4.9-lp151.2.7.1 opensuse-leap-15.1 x86_64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...