Описание
ELSA-2024-11049: squid security update (IMPORTANT)
[7:3.5.20-17.0.5.13]
- Fixed cve 2023-46846 for http and icap request/response smuggling [Orabug: 37326730]
Обновленные пакеты
Oracle Linux 7
Oracle Linux x86_64
squid
3.5.20-17.0.5.el7_9.13
squid-migration-script
3.5.20-17.0.5.el7_9.13
squid-sysvinit
3.5.20-17.0.5.el7_9.13
Связанные CVE
Связанные уязвимости
SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform Request/Response smuggling past firewall and frontend security systems.
SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform Request/Response smuggling past firewall and frontend security systems.
SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform Request/Response smuggling past firewall and frontend security systems.
SQUID is vulnerable to HTTP request smuggling, caused by chunked decod ...
Уязвимость декодера chunked прокси-сервера Squid, позволяющая нарушителю взаимодействовать с сервером напрямую