Описание
Security update for squid
This update for squid fixes the following issues:
- CVE-2023-46846: Request/Response smuggling in HTTP/1.1 and ICAP (bsc#1216500).
- CVE-2023-46847: Denial of Service in HTTP Digest Authentication (bsc#1216495).
- CVE-2023-46724: Fix validation of certificates with CN=* (bsc#1216803).
- CVE-2023-46848: Denial of Service in FTP (bsc#1216498).
Список пакетов
Image SLES15-SP4-Manager-Proxy-4-3-BYOS
Image SLES15-SP4-Manager-Proxy-4-3-BYOS-Azure
Image SLES15-SP4-Manager-Proxy-4-3-BYOS-EC2
Image SLES15-SP4-Manager-Proxy-4-3-BYOS-GCE
SUSE Linux Enterprise Module for Server Applications 15 SP4
SUSE Linux Enterprise Module for Server Applications 15 SP5
openSUSE Leap 15.4
openSUSE Leap 15.5
Ссылки
- Link for SUSE-SU-2023:4380-1
- E-Mail link for SUSE-SU-2023:4380-1
- SUSE Security Ratings
- SUSE Bug 1216495
- SUSE Bug 1216498
- SUSE Bug 1216500
- SUSE Bug 1216803
- SUSE CVE CVE-2023-46724 page
- SUSE CVE CVE-2023-46846 page
- SUSE CVE CVE-2023-46847 page
- SUSE CVE CVE-2023-46848 page
Описание
Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a specially crafted SSL Certificate in a server certificate chain. This attack is limited to HTTPS and SSL-Bump. This bug is fixed in Squid version 6.4. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. Those who you use a prepackaged version of Squid should refer to the package vendor for availability information on updated packages.
Затронутые продукты
Ссылки
- CVE-2023-46724
- SUSE Bug 1216803
Описание
SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform Request/Response smuggling past firewall and frontend security systems.
Затронутые продукты
Ссылки
- CVE-2023-46846
- SUSE Bug 1216500
Описание
Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication.
Затронутые продукты
Ссылки
- CVE-2023-46847
- SUSE Bug 1216495
Описание
Squid is vulnerable to Denial of Service, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Request messages or constructing ftp:// URLs from FTP Native input.
Затронутые продукты
Ссылки
- CVE-2023-46848
- SUSE Bug 1216498