squid-3.5.20-17.el7.8

エラータID: AXSA:2022-3878:02

Release date: 
Wednesday, October 5, 2022 - 12:58
Subject: 
squid-3.5.20-17.el7.8
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
High
Description: 

Squid is a high-performance proxy caching server for web clients, supporting FTP, Gopher, and HTTP data objects.

Security Fix(es):

* squid: buffer-over-read in SSPI and SMB authentication (CVE-2022-41318)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2022-41318
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. squid-3.5.20-17.el7.8.src.rpm
    MD5: 06bbec50b724b9bedc8e85c063fbb812
    SHA-256: 34d12bd61b8aa4aa1f73a82facd3fec1ad5aae027ce8ff7a7d1a0c263a0265e0
    Size: 2.33 MB

Asianux Server 7 for x86_64
  1. squid-3.5.20-17.el7.8.x86_64.rpm
    MD5: 2214a4f70670250fe6ec6a203664fc1e
    SHA-256: 6c15c695f647eb618a463e8b38b8fc9cc67cff46e25eed35265eb12f4df46a35
    Size: 3.14 MB
  2. squid-migration-script-3.5.20-17.el7.8.x86_64.rpm
    MD5: 8064c364fb4312b8b36f964de57b2658
    SHA-256: 016a8b6ed9203253c0e9c2087e441d754dacf30012e43ac66ebaf74effb88470
    Size: 50.25 kB