squid-3.5.20-17.el7.7

エラータID: AXSA:2022-3510:01

Release date: 
Monday, July 11, 2022 - 13:28
Subject: 
squid-3.5.20-17.el7.7
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
High
Description: 

Squid is a high-performance proxy caching server for Web clients,
supporting FTP, gopher, and HTTP data objects. Unlike traditional
caching software, Squid handles all requests in a single,
non-blocking, I/O-driven process. Squid keeps meta data and especially
hot objects cached in RAM, caches DNS lookups, supports non-blocking
DNS lookups, and implements negative caching of failed requests.

Squid consists of a main server program squid, a Domain Name System
lookup program (dnsserver), a program for retrieving FTP data
(ftpget), and some management and client tools.

Security Fix(es):

* squid: DoS when processing gopher server responses (CVE-2021-46784)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2021-46784
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. squid-3.5.20-17.el7.7.src.rpm
    MD5: 2a758abedd45f2db5e1d0b18eb06988a
    SHA-256: ba3a6dbfcf8b04bae7a78e46c7bf46338e09f39f9c2309dcb39dca35b0cc3de0
    Size: 2.33 MB

Asianux Server 7 for x86_64
  1. squid-3.5.20-17.el7.7.x86_64.rpm
    MD5: 7775364492315038b2427259df4ab9d5
    SHA-256: 329121d6d05b06bff62115b0d6d6d76ad7d29a91ab4877242c92d931ebe1f70a
    Size: 3.13 MB
  2. squid-migration-script-3.5.20-17.el7.7.x86_64.rpm
    MD5: d4eb5911e1381943cd1ad57de7f34798
    SHA-256: b41521cf5ddc688c87f4513dd79c2262f8c8789d6ba5d8430791fbfd283f2a3d
    Size: 50.10 kB