squid-3.5.20-15.el7

エラータID: AXSA:2020-4563:01

Release date: 
Thursday, April 2, 2020 - 08:10
Subject: 
squid-3.5.20-15.el7
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
Moderate
Description: 

Squid is a high-performance proxy caching server for web clients, supporting FTP, Gopher, and HTTP data objects.

Security Fix(es):

* squid: Incorrect pointer handling when processing ESI Responses can lead to denial of service (CVE-2018-1000024)

* squid: Incorrect pointer handling in HTTP processing and certificate download can lead to denial of service (CVE-2018-1000027)

* squid: XSS via user_name or auth parameter in cachemgr.cgi (CVE-2019-13345)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Asianux Server 7.8 Release Notes linked from the References section.

CVE-2018-1000024
The Squid Software Foundation Squid HTTP Caching Proxy version 3.0 to 3.5.27, 4.0 to 4.0.22 contains a Incorrect Pointer Handling vulnerability in ESI Response Processing that can result in Denial of Service for all clients using the proxy.. This attack appear to be exploitable via Remote server delivers an HTTP response payload containing valid but unusual ESI syntax.. This vulnerability appears to have been fixed in 4.0.23 and later.
CVE-2018-1000027
The Squid Software Foundation Squid HTTP Caching Proxy version prior to version 4.0.23 contains a NULL Pointer Dereference vulnerability in HTTP Response X-Forwarded-For header processing that can result in Denial of Service to all clients of the proxy. This attack appear to be exploitable via Remote HTTP server responding with an X-Forwarded-For header to certain types of HTTP request. This vulnerability appears to have been fixed in 4.0.23 and later.
CVE-2019-13345
The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_name or auth parameter.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. squid-3.5.20-15.el7.src.rpm
    MD5: a8438860e3c5876411dc9aae42e3b9b3
    SHA-256: 195e52886962ec17cd56758389809822520394306a9650d5fe024c5343a80229
    Size: 2.31 MB

Asianux Server 7 for x86_64
  1. squid-3.5.20-15.el7.x86_64.rpm
    MD5: ad04a5a62cb6a3783030f3c020520146
    SHA-256: c63157560087cf975d500741121ae66d65e6ec16ffe361edc24c2fd901205f92
    Size: 3.13 MB
  2. squid-migration-script-3.5.20-15.el7.x86_64.rpm
    MD5: 18984fcb4e09917389ba3d809b0227bc
    SHA-256: 3f660bcf4581bb9dbbedf13ce4e770839d8925dd0aaa6549a710d0a8b842a084
    Size: 48.32 kB