Oval Definition:oval:org.opensuse.security:def:72809
Revision Date:2020-12-01Version:1
Title:Security update for squid (Important)
Description:

This update for squid to version 4.9 fixes the following issues:

Security issues fixed:

- CVE-2019-13345: Fixed multiple cross-site scripting vulnerabilities in cachemgr.cgi (bsc#1140738). - CVE-2019-12526: Fixed potential remote code execution during URN processing (bsc#1156326). - CVE-2019-12523,CVE-2019-18676: Fixed multiple improper validations in URI processing (bsc#1156329). - CVE-2019-18677: Fixed Cross-Site Request Forgery in HTTP Request processing (bsc#1156328). - CVE-2019-18678: Fixed incorrect message parsing which could have led to HTTP request splitting issue (bsc#1156323). - CVE-2019-18679: Fixed information disclosure when processing HTTP Digest Authentication (bsc#1156324).

Other issues addressed:

* Fixed DNS failures when peer name was configured with any upper case characters * Fixed several rock cache_dir corruption issues
Family:unixClass:patch
Status:Reference(s):1051510
1065600
1065729
1071995
1083647
1085030
1109911
1111666
1113956
1114279
1118338
1120386
1133089
1137325
1140738
1141329
1141330
1141332
1141442
1142685
1145051
1145929
1148868
1156323
1156324
1156326
1156328
1156329
1157424
1158983
1159037
1159198
1159199
1161561
1161951
1162171
1163403
1163897
1164284
1164777
1164780
1164893
1165019
1165182
1165185
1165211
1165823
1165949
1166780
1166860
1166861
1166862
1166864
1166866
1166867
1166868
1166870
1166940
1166982
1167005
1167216
1167288
1167290
1167316
1167421
1167423
1167627
1167629
1168075
1168202
1168273
1168276
1168295
1168367
1168424
1168443
1168486
1168552
1168760
1168762
1168763
1168764
1168765
1168829
1168854
1168881
1168884
1168952
1169013
1169057
1169307
1169308
1169390
1169514
1169625
CVE-2019-12523
CVE-2019-12525
CVE-2019-12526
CVE-2019-12527
CVE-2019-12529
CVE-2019-12854
CVE-2019-13345
CVE-2019-18676
CVE-2019-18677
CVE-2019-18678
CVE-2019-18679
CVE-2019-19770
CVE-2019-3688
CVE-2019-3701
CVE-2019-9458
CVE-2020-10942
CVE-2020-11494
CVE-2020-11669
CVE-2020-8834
SUSE-SU-2019:2975-1
SUSE-SU-2020:1146-1
Platform(s):SUSE Linux Enterprise High Availability 15 SP1
SUSE Linux Enterprise Module for Server Applications 15 SP1
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise High Availability 15 SP1 is installed
  • AND Package Information
  • cluster-md-kmp-default-4.12.14-197.40 is installed
  • OR dlm-kmp-default-4.12.14-197.40 is installed
  • OR gfs2-kmp-default-4.12.14-197.40 is installed
  • OR kernel-default-4.12.14-197.40 is installed
  • OR ocfs2-kmp-default-4.12.14-197.40 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Server Applications 15 SP1 is installed
  • AND squid-4.9-5.11 is installed
  • BACK