squid34-3.4.14-15.0.1.AXS4

エラータID: AXSA:2021-1659:01

Release date: 
Tuesday, April 13, 2021 - 08:22
Subject: 
squid34-3.4.14-15.0.1.AXS4
Affected Channels: 
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity: 
High
Description: 

Squid is a high-performance proxy caching server for web clients, supporting
FTP, Gopher, and HTTP data objects.

Security Fix(es):

* squid: improper input validation may allow a trusted client to perform HTTP
request smuggling (CVE-2020-25097)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.

CVE-2020-25097
An issue was discovered in Squid through 4.13 and 5.x through 5.0.4. Due to
improper input validation, it allows a trusted client to perform HTTP Request
Smuggling and access services otherwise forbidden by the security controls. This
occurs for certain uri_whitespace configuration settings.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. squid34-3.4.14-15.0.1.AXS4.src.rpm
    MD5: ee3cb729ddb20eeeb762a682ba1d6a3d
    SHA-256: 4faeba17803f5d25e1b9300980a21eb14c8076dbca798ede8e97e019443b071a
    Size: 2.15 MB

Asianux Server 4 for x86
  1. squid34-3.4.14-15.0.1.AXS4.i686.rpm
    MD5: b0bf47b7056718a4b845b68abfb38aec
    SHA-256: cd41cd70658e594e05b825d8710826ac8534b281a9f783d22328b6cab0751514
    Size: 2.61 MB

Asianux Server 4 for x86_64
  1. squid34-3.4.14-15.0.1.AXS4.x86_64.rpm
    MD5: f81dbbb0c0d8d5baf6fcc2d6f1ba8ce4
    SHA-256: 9a83a7943d1d35347307be04df879caf186984b1e236f91d6e8e4d07f24abd3e
    Size: 2.64 MB