[SUSE-SU-2018:3771-2] Security update for squid

Severity Important
Affected Packages 4
CVEs 2

Security update for squid

This update for squid fixes the following issues:

Security issues fixed:

  • CVE-2018-19131: Fixed Cross-Site-Scripting vulnerability in the TLS error handling (bsc#1113668).
  • CVE-2018-19132: Fixed small memory leak in processing of SNMP packets (bsc#1113669).

Non-security issues fixed:

  • Create runtime directories needed when SMP mode is enabled (bsc#1112695, bsc#1112066).
  • Install license correctly (bsc#1082318).
ID
SUSE-SU-2018:3771-2
Severity
important
URL
https://www.suse.com/support/update/announcement/2018/suse-su-20183771-2/
Published
2018-12-06T12:52:59
(5 years ago)
Modified
2018-12-06T12:52:59
(5 years ago)
Rights
Copyright 2024 SUSE LLC. All rights reserved.
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/suse/squid?arch=x86_64&distro=sles-12&sp=4 suse squid < 3.5.21-26.12.1 sles-12 x86_64
Affected pkg:rpm/suse/squid?arch=s390x&distro=sles-12&sp=4 suse squid < 3.5.21-26.12.1 sles-12 s390x
Affected pkg:rpm/suse/squid?arch=ppc64le&distro=sles-12&sp=4 suse squid < 3.5.21-26.12.1 sles-12 ppc64le
Affected pkg:rpm/suse/squid?arch=aarch64&distro=sles-12&sp=4 suse squid < 3.5.21-26.12.1 sles-12 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...