MGASA-2021-0499
Dashboard / Vulnerabilities / MGASA-2021-0499
Summary: Updated squid packages fix security vulnerability
Details: Updated squid packages fix security vulnerability: Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure because of an out-of-bounds read in WCCP protocol data. This can be leveraged as part of a chain for remote code execution as nobody (CVE-2021-28116). Squid is updated to 4.17 that fixes this issue and other bugs.
References: https://advisories.mageia.org/MGASA-2021-0499.html, https://bugs.mageia.org/show_bug.cgi?id=29524, https://github.com/squid-cache/squid/security/advisories/GHSA-rgf3-9v3p-qp82, https://github.com/squid-cache/squid/commit/3896e584d7eeb321d7becbcedec872ffa868dd87, https://github.com/squid-cache/squid/commit/874e8b4ca0342a1c399ddadc1cf6998590fa46a6
Affected packages
Package
Name: squid
Purl: pkg:rpm/mageia/squid?arch=source&distro=mageia-8
Affected ranges
Type: ECOSYSTEM
Events:
