Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2021:4292

Опубликовано: 09 нояб. 2021
Источник: rocky
Оценка: Moderate

Описание

Moderate: squid:4 security, bug fix, and enhancement update

Squid is a high-performance proxy caching server for web clients, supporting FTP, Gopher, and HTTP data objects.

The following packages have been upgraded to a later upstream version: squid (4.15). (BZ#1964384)

Security Fix(es):

  • squid: denial of service in URN processing (CVE-2021-28651)

  • squid: denial of service issue in Cache Manager (CVE-2021-28652)

  • squid: denial of service in HTTP response processing (CVE-2021-28662)

  • squid: improper input validation in HTTP Range header (CVE-2021-31806)

  • squid: incorrect memory management in HTTP Range header (CVE-2021-31807)

  • squid: integer overflow in HTTP Range header (CVE-2021-31808)

  • squid: denial of service in HTTP response processing (CVE-2021-33620)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 8.5 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
libecapx86_642.module+el8.4.0+404+316a0dc5libecap-1.0.1-2.module+el8.4.0+404+316a0dc5.x86_64.rpm
libecap-develx86_642.module+el8.4.0+404+316a0dc5libecap-devel-1.0.1-2.module+el8.4.0+404+316a0dc5.x86_64.rpm

Показывать по

Связанные уязвимости

oracle-oval
больше 3 лет назад

ELSA-2021-4292: squid:4 security, bug fix, and enhancement update (MODERATE)

oracle-oval
почти 4 года назад

ELSA-2021-9465: squid security update (IMPORTANT)

suse-cvrf
около 4 лет назад

Security update for squid

suse-cvrf
около 4 лет назад

Security update for squid

suse-cvrf
около 4 лет назад

Security update for squid