gpp_maybe
Security update for squid
SUSE-SLE-SAP-12-SP2-2020-1227
This update for squid fixes the following issues: - CVE-2019-12519, CVE-2019-12521: fixes incorrect buffer handling that can result in cache poisoning, remote execution, and denial of service attacks when processing ESI responses (bsc#1169659). - CVE-2020-11945: fixes a potential remote execution vulnerability when using HTTP Digest Authentication (bsc#1170313). - CVE-2019-12520, CVE-2019-12524: fixes a potential ACL bypass, cache-bypass and cross-site scripting attack when processing invalid HTTP Request messages (bsc#1170423).
-
Release DateMay 8 2020
-
ReferencesBugzilla: 1170423, 1169659, 1170313
CVEs: CVE-2019-12521, CVE-2019-12519, CVE-2019-12524, CVE-2019-12520, CVE-2020-11945 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Enterprise Server for SAP Applications 12.2 ppc64le
-
Packages
SUSE Linux Enterprise Server for SAP Applications 12.2 x86_64
-
Packages