squid-5.5-6.el9.1

エラータID: AXSA:2023-6903:05

Release date: 
Tuesday, December 12, 2023 - 10:12
Subject: 
squid-5.5-6.el9.1
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

Squid is a high-performance proxy caching server for web clients, supporting FTP, Gopher, and HTTP data objects.

Security Fix(es):

* squid: Denial of Service in HTTP Digest Authentication (CVE-2023-46847)
* squid: Request/Response smuggling in HTTP/1.1 and ICAP (CVE-2023-46846)
* squid: denial of Service in FTP (CVE-2023-46848)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2023-46846
SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform Request/Response smuggling past firewall and frontend security systems.
CVE-2023-46847
Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication.
CVE-2023-46848
Squid is vulnerable to Denial of Service, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Request messages or constructing ftp:// URLs from FTP Native input.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. squid-5.5-6.el9.1.src.rpm
    MD5: 8939c1e18d29f9fb388940687cc87a7a
    SHA-256: c7583ae73c4f2ebc1e350fd23d7c139c7808054742744df1c90ca3ca04d475c6
    Size: 2.57 MB

Asianux Server 9 for x86_64
  1. squid-5.5-6.el9.1.x86_64.rpm
    MD5: 127e316ee06e2c31134bb589530d1412
    SHA-256: f2492c40f8037a5b013a485cb26b6edc4d5e4404e796f9a29fe6452d13463eff
    Size: 3.55 MB