MGASA-2021-0237
Dashboard / Vulnerabilities / MGASA-2021-0237
MGASA-2021-0237
Summary: Updated squid packages fix security vulnerabilities
Details: Updated squid packages fix security vulnerabilities: Due to improper input validation Squid is vulnerable to an HTTP Request Smuggling attack. This problem allows a trusted client to perform HTTP Request Smuggling and access services otherwise forbidden by Squid security controls (CVE-2020-25097). Joshua Rogers discovered that Squid incorrectly handled requests with the urn: scheme. A remote attacker could possibly use this issue to causeSquid to consume resources, leading to a denial of service (CVE-2021-28651). Joshua Rogers discovered that Squid incorrectly handled requests to the Cache Manager API. A remote attacker with access privileges could possibly use this issue to cause Squid to consume resources, leading to a denial of service (CVE-2021-28652). Joshua Rogers discovered that Squid incorrectly handled certain response headers. A remote attacker could possibly use this issue to cause Squid to crash, resulting in a denial of service (CVE-2021-28662). Joshua Rogers discovered that Squid incorrectly handled range request processing. A remote attacker could possibly use this issue to cause Squid to crash, resulting in a denial of service (CVE-2021-31806, CVE-2021-31807, CVE-2021-31808). Joshua Rogers discovered that Squid incorrectly handled certain HTTP responses. A remote attacker could possibly use this issue to cause Squid to crash, resulting in a denial of service (CVE-2021-33620). The squid package has been updated to version 4.15, fixing theese issues and other bugs.
References: https://advisories.mageia.org/MGASA-2021-0237.html, https://bugs.mageia.org/show_bug.cgi?id=28799, https://github.com/squid-cache/squid/security/advisories/GHSA-jvf6-h9gj-pmj6, https://github.com/squid-cache/squid/security/advisories/GHSA-ch36-9jhx-phm4, https://github.com/squid-cache/squid/security/advisories/GHSA-m47m-9hvw-7447, https://github.com/squid-cache/squid/security/advisories/GHSA-jjq6-mh2h-g39h, https://github.com/squid-cache/squid/security/advisories/GHSA-pxwq-f3qr-w2xf, https://github.com/squid-cache/squid/security/advisories/GHSA-572g-rvwr-6c7f, https://github.com/squid-cache/squid/commit/fa47a3bc4d382e28e7235d08750401b910e4b13a, https://github.com/squid-cache/squid/commit/648729b05673c6166c5d91c6ee4cda30cc164839, https://access.redhat.com/errata/RHSA-2021:1135, https://ubuntu.com/security/notices/USN-4981-1
Affected packages
Package
Name: squid
Purl: pkg:rpm/mageia/squid?arch=source&distro=mageia-7
Affected ranges
Type: ECOSYSTEM
Events:
