You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa squid

Sigurnosni nedostaci programskog paketa squid

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-4446-2
August 27, 2020

squid3 regression
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 18.04 LTS
– Ubuntu 16.04 LTS

Summary:

USN-4446-1 introduced a regression in Squid.

Software Description:
– squid3: Web proxy cache server

Details:

USN-4446-1 fixed vulnerabilities in Squid. The update introduced a
regression when using Squid with the icap or ecap protocols. This update
fixes the problem.

We apologize for the inconvenience.

Original advisory details:

Jeriko One discovered that Squid incorrectly handled caching certain
requests. A remote attacker could possibly use this issue to perform
cache-injection attacks or gain access to reverse proxy features such as
ESI. (CVE-2019-12520)
Jeriko One and Kristoffer Danielsson discovered that Squid incorrectly
handled certain URN requests. A remote attacker could possibly use this
issue to bypass access checks. (CVE-2019-12523)
Jeriko One discovered that Squid incorrectly handled URL decoding. A remote
attacker could possibly use this issue to bypass certain rule checks.
(CVE-2019-12524)
Jeriko One and Kristoffer Danielsson discovered that Squid incorrectly
handled input validation. A remote attacker could use this issue to cause
Squid to crash, resulting in a denial of service. (CVE-2019-18676)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
squid 3.5.27-1ubuntu1.8

Ubuntu 16.04 LTS:
squid 3.5.12-1ubuntu7.13

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4446-2
https://usn.ubuntu.com/4446-1
https://launchpad.net/bugs/1890265

Package Information:
https://launchpad.net/ubuntu/+source/squid3/3.5.27-1ubuntu1.8
https://launchpad.net/ubuntu/+source/squid3/3.5.12-1ubuntu7.13

—–BEGIN PGP SIGNATURE—–

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAl9HqbcACgkQZWnYVadE
vpP6gRAAhdKcUVo73pdNSyntCRPxTV0mtWpXZ7ZJ0CLS7s6wpomUmFF4dURLZy8K
nD74+a48b0uKAovvsGAaUhQCbf+0yux8LW7s/mQJkFautwBP2xsDObzusH3lRmmd
b/iFIWCqpBnwWGkvw9TT0q/JQLm9vhnd5sr9Qm+HK/+KD3i2INADYqssaOK1+q6R
r4WcQKppsBe+q/DZafHDVti6wjX9clPWGBk7z0N8g/TRL3JotEZ6f6BbAPnq/Z3V
ByhPKrwu0WiBrx04WcGa7uQw8jtMqWMKmpsg86RNdrqqcHeSjhM0uMiXns93z3zY
1wYeWykFzCESTkg4lv2LAG7V9xMgzVmhHbklt3ooOdDKjS9NG25vJ310w1T6a8rj
2jOnxPy5R8R8yEMu+9/4e1yNri+qOMnJP+QYYeTNcrPqJAQh/K+QVcophjgPm1Qm
iFJ6NdhVODbcCM5Ag2lWJNBoeDmQKVRy0rz/QLLVLwjgS4wTyofEg4oYEAtY0xye
iMjlJw7UndT58Mv8Ir0u9JiO981GMNLDnnwl+a/kayteav4wxYQQydFW7YRd3qae
5SJMG2mA8p74Ja75v0s/I/s3PsEDtiv+yIytlq178tQgzjmWRfuaXTI84lloaaRd
UoP2Pu40r6P17sDWIRdJfG1QfH91b4eYACsTFsJpOJEs/zBJdEc=
=7NTI
—–END PGP SIGNATURE—–

ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

==========================================================================
Ubuntu Security Notice USN-4477-1
August 27, 2020

squid vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 20.04 LTS

Summary:

Several security issues were fixed in Squid.

Software Description:
– squid: Web proxy cache server

Details:

Amit Klein discovered that Squid incorrectly validated certain data. A
remote attacker could possibly use this issue to perform an HTTP request
smuggling attack, resulting in cache poisoning. (CVE-2020-15810)

Régis Leroy discovered that Squid incorrectly validated certain data. A
remote attacker could possibly use this issue to perform an HTTP request
splitting attack, resulting in cache poisoning. (CVE-2020-15811)

Lubos Uhliarik discovered that Squid incorrectly handled certain Cache
Digest response messages sent by trusted peers. A remote attacker could
possibly use this issue to cause Squid to consume resources, resulting in a
denial of service. (CVE-2020-24606)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
squid 4.10-1ubuntu1.2

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4477-1
CVE-2020-15810, CVE-2020-15811, CVE-2020-24606

Package Information:
https://launchpad.net/ubuntu/+source/squid/4.10-1ubuntu1.2

—–BEGIN PGP SIGNATURE—–

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAl9H+DQACgkQZWnYVadE
vpMhZw/+JpuLqODnqYAkg6vfW/RMWNMjB8ABqdx2ogo4OjFD/pgKZCC6AdcrYiPQ
kmVZqItaqi+heH/StRkVe1gsBUjg9yrR+QFyZUR+T+z163eBVSPjR4ZmY4RSKI+B
4wa6I1sIoNz8aYYjFRVbrTb55P8mzV6ytSZxnomoduh6U+NeiOS+yXfDFzD5CaKQ
Rx6b3jNqza6a4HysrgaBTAg/xzDSI7CUUJY6yMTx+y+0fJhp3ezRz8DlbBySNyoU
NeAGw4wf7mB5ZTKdliLDerBo+k1NJlrdkwXgD518xkWuoS2sykAnM41+qsbRToCx
3PIvtourizAFs+sK6Hf2808un0WX0DdT/knDqZbZg+NvY448kapOPAGXWmVN1Umz
rNhgLJDrkQcEsCKanKK6AkXXtjvb1hUcUqmFvc0NDJQLCkL3vyyYx2EcUj4G9JSA
xSRaBoT7mkiAMBNJHdpYkz2roE4GGXmgQ4qWRlJPbt9hgZ3+hGY+C66CUlbIlj+4
LaaUf80IpGX14FyennIeo04EcScFQ+jzVf6t14ThzwJ24BFNHreqXrbRH7tn+53A
UgovHunEL9hMe44xoEnlu9PHsdpqDGpahKtgp2LHXbpfzqorWGFT1juqhR0jlPzK
jIXS5dxNQHKd+/fYTSLdwr9P9prUfi9zSX+ismanYnQx04GAhlU=
=S3uz
—–END PGP SIGNATURE—–

AutorGoran Culibrk
Cert idNCERT-REF-2020-08-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Sigurnosni nedostaci programskog paketa Redis

Otkriveni su sigurnosni nedostaci u programskom paketu Redis za operacijski sustav Gentoo. Otkriveni nedostaci potencijalnim napadačima omogućuju izazivanje DoS stanja....

Close