Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2024-1787

Опубликовано: 11 апр. 2024
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2024-1787: squid security update (IMPORTANT)

[7:3.5.20-17.0.1]

  • Mutiple CVE fixes for squid [Orabug: 33146289]
  • Resolves: CVE-2021-28651 squid: Bug 5104: Memory leak in RFC 2169 response parsing (#778)
  • Resolves: CVE-2021-28652 squid: Bug 5106: Broken cache manager URL parsing (#788)
  • Resolves: CVE-2021-31806,31807,31808 squid: Handle more Range requests (#790)
  • Resolves: CVE-2021-33620 squid: Handle more partial responses (#791)

[7:3.5.20-17.10]

  • Resolves: RHEL-16779 - squid: NULL pointer dereference in the gopher protocol code -- Remove support for Gopher protocol (CVE-2023-46728)
  • Resolves: RHEL-18176 - squid: Buffer over-read in the HTTP Message processing feature (CVE-2023-49285)
  • Resolves: RHEL-18171 - squid: Incorrect Check of Function Return Value In Helper Process management (CVE-2023-49286)
  • Resolves: RHEL-16758 - squid: Denial of Service in SSL Certificate validation (CVE-2023-46724)
  • Resolves: RHEL-19557 - squid: denial of service in HTTP request parsing (CVE-2023-50269)
  • Resolves: RHEL-26082 - squid: denial of service in HTTP header parser (CVE-2024-25617)

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

squid

3.5.20-17.0.1.el7_9.10

squid-migration-script

3.5.20-17.0.1.el7_9.10

squid-sysvinit

3.5.20-17.0.1.el7_9.10

Oracle Linux x86_64

squid

3.5.20-17.0.1.el7_9.10

squid-migration-script

3.5.20-17.0.1.el7_9.10

squid-sysvinit

3.5.20-17.0.1.el7_9.10

Связанные уязвимости

rocky
около 2 лет назад

Important: squid:4 security update

oracle-oval
около 2 лет назад

ELSA-2024-0071: squid security update (IMPORTANT)

oracle-oval
около 2 лет назад

ELSA-2024-0046: squid:4 security update (IMPORTANT)

rocky
8 месяцев назад

Important: squid:4 security update

oracle-oval
почти 2 года назад

ELSA-2024-1376: squid security update (IMPORTANT)

Уязвимость ELSA-2024-1787