[SUSE-SU-2022:3531-1] Security update for squid
Severity
Important
Affected Packages
4
CVEs
2
Security update for squid
This update for squid fixes the following issues:
Updated squid to version 5.7:
- CVE-2022-41317: Fixed exposure of sensitive information in cache manager (bsc#1203677).
- CVE-2022-41318: Fixed buffer overread in SSPI and SMB Authentication (bsc#1203680).
Package | Affected Version |
---|---|
pkg:rpm/suse/squid?arch=x86_64&distro=opensuse-leap-15.4 | < 5.7-150400.3.6.1 |
pkg:rpm/suse/squid?arch=s390x&distro=opensuse-leap-15.4 | < 5.7-150400.3.6.1 |
pkg:rpm/suse/squid?arch=ppc64le&distro=opensuse-leap-15.4 | < 5.7-150400.3.6.1 |
pkg:rpm/suse/squid?arch=aarch64&distro=opensuse-leap-15.4 | < 5.7-150400.3.6.1 |
- ID
- SUSE-SU-2022:3531-1
- Severity
- important
- URL
- https://www.suse.com/support/update/announcement/2022/suse-su-20223531-1/
- Published
-
2022-10-06T07:21:55
(23 months ago) - Modified
-
2022-10-06T07:21:55
(23 months ago) - Rights
- Copyright 2024 SUSE LLC. All rights reserved.
- Other Advisories
-
- ALAS-2023-1677
- ALAS-2023-1687
- ALAS2-2023-1907
- ALAS2-2023-1950
- ALPINE:CVE-2022-41317
- ALPINE:CVE-2022-41318
- ALSA-2022:6775
- ALSA-2022:6839
- DSA-5258-1
- ELSA-2022-6775
- ELSA-2022-6815
- ELSA-2022-6839
- FEDORA-2022-102c59d287
- FEDORA-2022-23e6ee1fb9
- FEDORA-2022-c8cad41c95
- FREEBSD:F9ADA0B5-3D80-11ED-9330-080027F5FEC9
- RHSA-2022:6775
- RHSA-2022:6815
- RHSA-2022:6839
- RLSA-2022:6775
- SUSE-SU-2022:3532-1
- SUSE-SU-2022:3533-1
- SUSE-SU-2022:3596-1
- USN-5641-1
- USN-6857-1
Source | # ID | Name | URL |
---|---|---|---|
Suse | SUSE ratings | https://www.suse.com/support/security/rating/ | |
Suse | URL of this CSAF notice | https://ftp.suse.com/pub/projects/security/csaf/suse-su-2022_3531-1.json | |
Suse | URL for SUSE-SU-2022:3531-1 | https://www.suse.com/support/update/announcement/2022/suse-su-20223531-1/ | |
Suse | E-Mail link for SUSE-SU-2022:3531-1 | https://lists.suse.com/pipermail/sle-security-updates/2022-October/012509.html | |
Bugzilla | SUSE Bug 1203677 | https://bugzilla.suse.com/1203677 | |
Bugzilla | SUSE Bug 1203680 | https://bugzilla.suse.com/1203680 | |
CVE | SUSE CVE CVE-2022-41317 page | https://www.suse.com/security/cve/CVE-2022-41317/ | |
CVE | SUSE CVE CVE-2022-41318 page | https://www.suse.com/security/cve/CVE-2022-41318/ |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/suse/squid?arch=x86_64&distro=opensuse-leap-15.4 | suse | squid | < 5.7-150400.3.6.1 | opensuse-leap-15.4 | x86_64 | |
Affected | pkg:rpm/suse/squid?arch=s390x&distro=opensuse-leap-15.4 | suse | squid | < 5.7-150400.3.6.1 | opensuse-leap-15.4 | s390x | |
Affected | pkg:rpm/suse/squid?arch=ppc64le&distro=opensuse-leap-15.4 | suse | squid | < 5.7-150400.3.6.1 | opensuse-leap-15.4 | ppc64le | |
Affected | pkg:rpm/suse/squid?arch=aarch64&distro=opensuse-leap-15.4 | suse | squid | < 5.7-150400.3.6.1 | opensuse-leap-15.4 | aarch64 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |