[ELSA-2020-3623] squid:4 security update

Severity Important
Affected Packages 3
CVEs 2

libecap
squid
[7:4.4-8.2]
- Resolves: #1872345 - CVE-2020-15811 squid:4/squid: HTTP Request Splitting
could result in cache poisoning
- Resolves: #1872330 - CVE-2020-15810 squid:4/squid: HTTP Request Smuggling
could result in cache poisoning

[7:4.4-8.1]
- Resolves: #1828368 - CVE-2019-12519 squid: improper check for new member in
ESIExpression::Evaluate allows for stack buffer overflow
- Resolves: #1828367 - CVE-2020-11945 squid: improper access restriction upon
Digest Authentication nonce replay could lead to remote code execution
- Resolves: #1829402 - CVE-2019-12525 squid:4/squid: parsing of header
Proxy-Authentication leads to memory corruption

Package Affected Version
pkg:rpm/oraclelinux/squid?distro=oraclelinux-8.2 < 4.4-8.module+el8.2.0+7778+aff7482f.2
pkg:rpm/oraclelinux/libecap?distro=oraclelinux-8.1 < 1.0.1-2.module+el8.1.0+5405+03b963f4
pkg:rpm/oraclelinux/libecap-devel?distro=oraclelinux-8.1 < 1.0.1-2.module+el8.1.0+5405+03b963f4
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/oraclelinux/squid?distro=oraclelinux-8.2 oraclelinux squid < 4.4-8.module+el8.2.0+7778+aff7482f.2 oraclelinux-8.2
Affected pkg:rpm/oraclelinux/libecap?distro=oraclelinux-8.1 oraclelinux libecap < 1.0.1-2.module+el8.1.0+5405+03b963f4 oraclelinux-8.1
Affected pkg:rpm/oraclelinux/libecap-devel?distro=oraclelinux-8.1 oraclelinux libecap-devel < 1.0.1-2.module+el8.1.0+5405+03b963f4 oraclelinux-8.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...