ELSA-2020-1068

ELSA-2020-1068 - squid security and bug fix update

Type:SECURITY
Severity:MODERATE
Release Date:2020-04-06

Description


[7:3.5.20-15]
- Resolves: #1690551 - Squid cache_peer DNS lookup failed when not all lower
case
- Resolves: #1680022 - squid cant display download/upload packet size for HTTPS
sites
- Resolves: #1717430 - Excessive memory usage when running out of descriptors
- Resolves: #1676420 - Cache siblings return wrongly cached gateway timeouts
- Resolves: #1729435 - CVE-2019-13345 squid: XSS via user_name or auth parameter
in cachemgr.cgi
- Resolves: #1582301 - CVE-2018-1000024 CVE-2018-1000027 squid: various flaws

[7:3.5.20-13]
- Resolves: #1620546 - migration of upstream squid


Related CVEs


CVE-2018-1000024
CVE-2019-13345
CVE-2018-1000027

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 7 (aarch64) squid-3.5.20-15.el7.src.rpm9385a606ae9a001a20ea96160794c407ELSA-2021-1135
squid-3.5.20-15.el7.aarch64.rpm34e5f4cf0234140ca18bda241a1af5b7ELSA-2021-1135
squid-migration-script-3.5.20-15.el7.aarch64.rpm63447bf3e96ec579aa5805a6b1ca7282ELSA-2021-1135
squid-sysvinit-3.5.20-15.el7.aarch64.rpm35581e3f69ea795e522efb751c666741ELSA-2021-1135
Oracle Linux 7 (x86_64) squid-3.5.20-15.el7.src.rpm9385a606ae9a001a20ea96160794c407ELSA-2021-1135
squid-3.5.20-15.el7.x86_64.rpm1733430c0133afd881e2b15d3fc28f46ELSA-2021-1135
squid-migration-script-3.5.20-15.el7.x86_64.rpm18c020b9dc3ce228119aea5e96d55cbaELSA-2021-1135
squid-sysvinit-3.5.20-15.el7.x86_64.rpm1444748da6e4b3bfc1604e5a6ace3bfbELSA-2021-1135



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete