[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253928

 
 

909

 
 

198006

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2021:1838-1 -- SLES squid

ID: oval:org.secpod.oval:def:89044383Date: (C)2021-06-18   (M)2024-04-25
Class: PATCHFamily: unix




This update for squid fixes the following issues: - update to 4.15: - CVE-2021-28652: Broken cache manager URL parsing - CVE-2021-28651: Memory leak in RFC 2169 response parsing - CVE-2021-28662: Limit HeaderLookupTable_t::lookup to BadHdr and specific IDs - CVE-2021-31806: Handle more Range requests - CVE-2020-25097: HTTP Request Smuggling vulnerability - Handle more partial responses - fix previous change to reinstante permissions macros, because the wrong path has been used . - use libexecdir instead of libdir to conform to recent changes in Factory . - Reinstate permissions macros for pinger binary, because the permissions package is also responsible for setting up the cap_net_raw capability, currently a fresh squid install doesn"t get a capability bit at all . - Change pinger and basic_pam_auth helper to use standard permissions. pinger uses cap_net_raw=ep instead

Platform:
SUSE Linux Enterprise Server 12 SP5
Product:
squid
Reference:
SUSE-SU-2021:1838-1
CVE-2020-25097
CVE-2021-28651
CVE-2021-28652
CVE-2021-28662
CVE-2021-31806
CVE    5
CVE-2021-28662
CVE-2020-25097
CVE-2021-28651
CVE-2021-31806
...

© SecPod Technologies