[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250108

 
 

909

 
 

196064

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

squid: Multiple issues (CVE-2020-15810, CVE-2020-15811, CVE-2020-24606)

ID: oval:org.secpod.oval:def:1801752Date: (C)2020-12-23   (M)2024-02-08
Class: PATCHFamily: unix




Due to incorrect data validation Squid is vulnerable to HTTP Request Smuggling attacks against HTTP and HTTPS traffic. This leads to cache poisoning. Affected Versions: 2.5-3.5.28, 4.0-4.12, 5.0.1-5.0.3Due to incorrect data validation Squid is vulnerable to HTTP Request Splitting attacks against HTTP and HTTPS traffic. This leads to cache poisoning. Affected Versions: 2.7-3.5.28, 4.0-4.12, 5.0.1-5.0.3Due to Improper Input Validation Squid is vulnerable to a Denial of Service attack against the machine operating Squid. Affected Versions: 3.0-4.12, 5.0.1-5.0.3 Fixed Versions: 4.13, 5.0.4

Platform:
Alpine Linux 3.10
Alpine Linux 3.11
Alpine Linux 3.12
Alpine Linux 3.9
Product:
squid
Reference:
11896
CVE-2020-15810
CVE-2020-15811
CVE-2020-24606
CVE    3
CVE-2020-15810
CVE-2020-15811
CVE-2020-24606
CPE    4
cpe:/o:alpinelinux:alpine_linux:3.11
cpe:/o:alpinelinux:alpine_linux:3.9
cpe:/o:alpinelinux:alpine_linux:3.10
cpe:/a:squid-cache:squid
...

© SecPod Technologies