Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2017:0110-1

Опубликовано: 11 янв. 2017
Источник: suse-cvrf

Описание

Security update for squid3

This update for squid3 fixes the following issues:

  • CVE-2016-10002: Fixed incorrect processing of responses to If-None-Modified HTTP conditional requests. This allowed responses containing private data to clients it should not have reached (bsc#1016168)
  • CVE-2014-9749: Prevent nonce replay in Digest authentication, preventing the reuse of stale auth tokens (bsc#949942)

Список пакетов

SUSE Linux Enterprise Server 11 SP4
squid3-3.1.23-8.16.36.1
SUSE Linux Enterprise Server for SAP Applications 11 SP4
squid3-3.1.23-8.16.36.1

Описание

Squid 3.4.4 through 3.4.11 and 3.5.0.1 through 3.5.1, when Digest authentication is used, allow remote authenticated users to retain access by leveraging a stale nonce, aka "Nonce replay vulnerability."


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:squid3-3.1.23-8.16.36.1
SUSE Linux Enterprise Server for SAP Applications 11 SP4:squid3-3.1.23-8.16.36.1

Ссылки

Описание

Incorrect processing of responses to If-None-Modified HTTP conditional requests in Squid HTTP Proxy 3.1.10 through 3.1.23, 3.2.0.3 through 3.5.22, and 4.0.1 through 4.0.16 leads to client-specific Cookie data being leaked to other clients. Attack requests can easily be crafted by a client to probe a cache for this information.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:squid3-3.1.23-8.16.36.1
SUSE Linux Enterprise Server for SAP Applications 11 SP4:squid3-3.1.23-8.16.36.1

Ссылки