ELSA-2022-6815

ELSA-2022-6815 - squid security update

Type:SECURITY
Severity:IMPORTANT
Release Date:2022-10-07

Description


[7:3.5.20-17.0.1]
- Mutiple CVE fixes for squid [Orabug: 33146289]
- Resolves: CVE-2021-28651 squid: Bug 5104: Memory leak in RFC 2169 response parsing (#778)
- Resolves: CVE-2021-28652 squid: Bug 5106: Broken cache manager URL parsing (#788)
- Resolves: CVE-2021-31806,31807,31808 squid: Handle more Range requests (#790)
- Resolves: CVE-2021-33620 squid: Handle more partial responses (#791)

[7:3.5.20-17.8]
- Resolves: #2130254 - CVE-2022-41318 squid: buffer-over-read in SSPI and SMB
authentication


Related CVEs


CVE-2022-41318

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 7 (aarch64) squid-3.5.20-17.0.1.el7_9.8.src.rpmc0cf6a794462190f28fa5e66828bd962-
squid-3.5.20-17.0.1.el7_9.8.aarch64.rpm34fd419dc58a659463aae7215d9eef45-
squid-migration-script-3.5.20-17.0.1.el7_9.8.aarch64.rpmc847e4b21e26ed986de2ff28c7111671-
squid-sysvinit-3.5.20-17.0.1.el7_9.8.aarch64.rpm9b59c4bd42c8a42e008823e45e839329-
Oracle Linux 7 (x86_64) squid-3.5.20-17.0.1.el7_9.8.src.rpmc0cf6a794462190f28fa5e66828bd962-
squid-3.5.20-17.0.1.el7_9.8.x86_64.rpm3c70e62850f0ac9c48f1f7cc5d579c11-
squid-migration-script-3.5.20-17.0.1.el7_9.8.x86_64.rpm0ee408d1ae03724477546ed3bf7946af-
squid-sysvinit-3.5.20-17.0.1.el7_9.8.x86_64.rpm96bccc0fc5be92978015e8f01e2dcd6f-



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete