gpp_maybe
Security update for squid
SUSE-SLE-SAP-12-SP2-2020-661
This update for squid fixes the following issues: - CVE-2019-12528: Fixed an information disclosure flaw in the FTP gateway (bsc#1162689). - CVE-2019-12526: Fixed potential remote code execution during URN processing (bsc#1156326). - CVE-2019-12523,CVE-2019-18676: Fixed multiple improper validations in URI processing (bsc#1156329). - CVE-2019-18677: Fixed Cross-Site Request Forgery in HTTP Request processing (bsc#1156328). - CVE-2019-18678: Fixed incorrect message parsing which could have led to HTTP request splitting issue (bsc#1156323). - CVE-2019-18679: Fixed information disclosure when processing HTTP Digest Authentication (bsc#1156324). - CVE-2020-8449: Fixed a buffer overflow when squid is acting as reverse-proxy (bsc#1162687). - CVE-2020-8450: Fixed a buffer overflow when squid is acting as reverse-proxy (bsc#1162687). - CVE-2020-8517: Fixed a buffer overflow in ext_lm_group_acl when processing NTLM Authentication credentials (bsc#1162691).
-
Release DateMar 12 2020
-
ReferencesBugzilla: 1162687, 1156323, 1156328, 1156329, 1156326, 1162691, 1162689, 1156324
CVEs: CVE-2019-12523, CVE-2019-18676, CVE-2019-18677, CVE-2019-18678, CVE-2019-12526, CVE-2019-18679, CVE-2020-8449, CVE-2020-8450, CVE-2019-12528, CVE-2020-8517 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Enterprise Server for SAP Applications 12.2 ppc64le
-
Packages
SUSE Linux Enterprise Server for SAP Applications 12.2 x86_64
-
Packages