[RHSA-2016:1573] squid security update
Severity
Moderate
Affected Packages
4
CVEs
1
Squid is a high-performance proxy caching server for web clients, supporting FTP, Gopher, and HTTP data objects.
Security Fix(es):
- It was found that the fix for CVE-2016-4051 released via RHSA-2016:1138 did not properly prevent the stack overflow in the munge_other_line() function. A remote attacker could send specially crafted data to the Squid proxy, which would exploit the cachemgr CGI utility, possibly triggering execution of arbitrary code. (CVE-2016-5408)
Red Hat would like to thank Amos Jeffries (Squid) for reporting this issue.
Package | Affected Version |
---|---|
pkg:rpm/redhat/squid?arch=x86_64&distro=redhat-6.8 | < 3.1.23-16.el6_8.6 |
pkg:rpm/redhat/squid?arch=s390x&distro=redhat-6.8 | < 3.1.23-16.el6_8.6 |
pkg:rpm/redhat/squid?arch=ppc64&distro=redhat-6.8 | < 3.1.23-16.el6_8.6 |
pkg:rpm/redhat/squid?arch=i686&distro=redhat-6.8 | < 3.1.23-16.el6_8.6 |
- ID
- RHSA-2016:1573
- Severity
- moderate
- URL
- https://access.redhat.com/errata/RHSA-2016:1573
- Published
-
2016-08-04T00:00:00
(8 years ago) - Modified
-
2016-08-04T00:00:00
(8 years ago) - Rights
- Copyright 2016 Red Hat, Inc.
- Other Advisories
Source | # ID | Name | URL |
---|---|---|---|
Bugzilla | 1359203 | https://bugzilla.redhat.com/1359203 | |
RHSA | RHSA-2016:1573 | https://access.redhat.com/errata/RHSA-2016:1573 | |
CVE | CVE-2016-5408 | https://access.redhat.com/security/cve/CVE-2016-5408 |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/redhat/squid?arch=x86_64&distro=redhat-6.8 | redhat | squid | < 3.1.23-16.el6_8.6 | redhat-6.8 | x86_64 | |
Affected | pkg:rpm/redhat/squid?arch=s390x&distro=redhat-6.8 | redhat | squid | < 3.1.23-16.el6_8.6 | redhat-6.8 | s390x | |
Affected | pkg:rpm/redhat/squid?arch=ppc64&distro=redhat-6.8 | redhat | squid | < 3.1.23-16.el6_8.6 | redhat-6.8 | ppc64 | |
Affected | pkg:rpm/redhat/squid?arch=i686&distro=redhat-6.8 | redhat | squid | < 3.1.23-16.el6_8.6 | redhat-6.8 | i686 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |