SUSE-SU-2021:1961-1
Dashboard / Vulnerabilities / SUSE-SU-2021:1961-1
SUSE-SU-2021:1961-1
Summary: Security update for squid
Details: This update for squid fixes the following issues: - update to 4.15: - CVE-2021-28652: Broken cache manager URL parsing (bsc#1185918) - CVE-2021-28651: Memory leak in RFC 2169 response parsing (bsc#1185921) - CVE-2021-28662: Limit HeaderLookupTable_t::lookup() to BadHdr and specific IDs (bsc#1185919) - CVE-2021-31806: Handle more Range requests (bsc#1185916) - CVE-2020-25097: HTTP Request Smuggling vulnerability (bsc#1183436) - Handle more partial responses (bsc#1185923) - fix previous change to reinstante permissions macros, because the wrong path has been used (bsc#1171569). - use libexecdir instead of libdir to conform to recent changes in Factory (bsc#1171164). - Reinstate permissions macros for pinger binary, because the permissions package is also responsible for setting up the cap_net_raw capability, currently a fresh squid install doesn't get a capability bit at all (bsc#1171569). - Change pinger and basic_pam_auth helper to use standard permissions. pinger uses cap_net_raw=ep instead (bsc#1171569)
References: https://www.suse.com/support/update/announcement/2021/suse-su-20211961-1/, https://bugzilla.suse.com/1171164, https://bugzilla.suse.com/1171569, https://bugzilla.suse.com/1183436, https://bugzilla.suse.com/1185916, https://bugzilla.suse.com/1185918, https://bugzilla.suse.com/1185919, https://bugzilla.suse.com/1185921, https://bugzilla.suse.com/1185923, https://www.suse.com/security/cve/CVE-2020-25097, https://www.suse.com/security/cve/CVE-2021-28651, https://www.suse.com/security/cve/CVE-2021-28652, https://www.suse.com/security/cve/CVE-2021-28662, https://www.suse.com/security/cve/CVE-2021-31806
Affected packages
Package
Name: squid
Purl: pkg:rpm/suse/squid&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP2
Affected ranges
Type: ECOSYSTEM
Events:
