MGASA-2019-0265
Dashboard / Vulnerabilities / MGASA-2019-0265
MGASA-2019-0265
Summary: Updated squid packages fix security vulnerabilities
Details: Updated squid packages fix security vulnerabilities: It was discovered that Squid incorrectly handled Digest authentication. A remote attacker could possibly use this issue to cause Squid to crash, resulting in a denial of service (CVE-2019-12525). It was discovered that Squid incorrectly handled Basic authentication. A remote attacker could possibly use this issue to cause Squid to crash, resulting in a denial of service (CVE-2019-12529). It was discovered that Squid incorrectly handled the cachemgr.cgi web module. A remote attacker could possibly use this issue to conduct cross-site scripting (XSS) attacks (CVE-2019-13345).
References: https://advisories.mageia.org/MGASA-2019-0265.html, https://bugs.mageia.org/show_bug.cgi?id=25110, https://usn.ubuntu.com/4059-1/, https://usn.ubuntu.com/4065-1/
Affected packages
Package
Name: squid
Purl: pkg:rpm/mageia/squid?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
