Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2019:3476

Опубликовано: 05 нояб. 2019
Источник: rocky
Оценка: Moderate

Описание

Moderate: squid:4 security and bug fix update

Squid is a high-performance proxy caching server for web clients, supporting FTP, Gopher, and HTTP data objects.

Security Fix(es):

  • squid: XSS via user_name or auth parameter in cachemgr.cgi (CVE-2019-13345)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 8.1 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
libecapx86_642.module+el8.4.0+404+316a0dc5libecap-1.0.1-2.module+el8.4.0+404+316a0dc5.x86_64.rpm
libecap-develx86_642.module+el8.4.0+404+316a0dc5libecap-devel-1.0.1-2.module+el8.4.0+404+316a0dc5.x86_64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 6 лет назад

The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_name or auth parameter.

CVSS3: 4.3
redhat
почти 6 лет назад

The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_name or auth parameter.

CVSS3: 6.1
nvd
почти 6 лет назад

The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_name or auth parameter.

CVSS3: 6.1
debian
почти 6 лет назад

The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_ ...

suse-cvrf
почти 6 лет назад

Security update for squid