[ELSA-2015-2378] squid security and bug fix update

Severity Moderate
Affected Packages 2
CVEs 1

- Related: #1186768 - removing patch, because of missing tests and
incorrent patch

- Related: #1102842 - squid rpm package misses /var/run/squid needed for
smp mode. Squid needs write access to /var/run/squid.

- Related: #1102842 - squid rpm package misses /var/run/squid needed for
smp mode. Creation of /var/run/squid was also needed to be in SPEC file.

- Related: #1102842 - squid rpm package misses /var/run/squid needed for
smp mode. Creation of this directory was moved to tmpfiles.d conf file.

- Related: #1102842 - squid rpm package misses /var/run/squid needed for
smp mode. Creation of this directory was moved to service file.

- Resolves: #1263338 - squid with digest auth on big endian systems
start looping

- Resolves: #1186768 - security issue: Nonce replay vulnerability
in Digest authentication

- Resolves: #1225640 - squid crashes by segfault when it reboots

- Resolves: #1102842 - squid rpm package misses /var/run/squid needed for
smp mode

- Resolves: #1233265 - CVE-2015-3455 squid: incorrect X509 server
certificate validation

- Resolves: #1080042 - Supply a firewalld service file with squid

- Resolves: #1161600 - Squid does not serve cached responses
with Vary headers

- Resolves: #1198778 - Filedescriptor leaks on snmp

- Resolves: #1204375 - squid sends incorrect ssl chain breaking newer gnutls
using applications

(8 years ago)
(8 years ago)
Copyright 2015 Oracle, Inc.
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/oraclelinux/squid?distro=oraclelinux-7 oraclelinux squid < 3.3.8-26.el7 oraclelinux-7
Affected pkg:rpm/oraclelinux/squid-sysvinit?distro=oraclelinux-7 oraclelinux squid-sysvinit < 3.3.8-26.el7 oraclelinux-7
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date