MGASA-2018-0095
Dashboard / Vulnerabilities / MGASA-2018-0095
MGASA-2018-0095
Summary: Updated squid packages fix security vulnerabilities
Details: Due to incorrect pointer handling Squid is vulnerable to denial of service attack when processing ESI responses. This problem allows a remote server delivering certain ESI response syntax to trigger a denial of service for all clients accessing the Squid service (SQUID-2018:1). Due to incorrect pointer handling Squid is vulnerable to denial of service attack when processing ESI responses or downloading intermediate CA certificates. This problem allows a remote client delivering certain HTTP requests in conjunction with certain trusted server responses to trigger a denial of service for all clients accessing the Squid service (SQUID-2018:2).
References: https://advisories.mageia.org/MGASA-2018-0095.html, https://bugs.mageia.org/show_bug.cgi?id=22440, http://www.squid-cache.org/Advisories/SQUID-2018_1.txt, http://www.squid-cache.org/Advisories/SQUID-2018_2.txt
Affected packages
Package
Name: squid
Purl: pkg:rpm/mageia/squid?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
