shield Security update for squid
SUSE-SLE-SERVER-12-SP2-2017-67


This update for squid fixes the following issues: - CVE-2016-10003: Prevent incorrect forwarding of cached private responses when Collapsed Forwarding feature is enabled. This allowed remote attacker (proxy user) to discover private and sensitive information about another user (bsc#1016169). - CVE-2016-10002: Fixed incorrect processing of responses to If-None-Modified HTTP conditional requests. This allowed responses containing private data to clients it should not have reached (bsc#1016168). - CVE-2014-9749: Prevent nonce replay in Digest authentication, preventing the reuse of stale auth tokens (bsc#949942).


cloud_download Downloads

SUSE Linux Enterprise Server 12.2 x86_64
  • Packages
    squid
    A fully featured HTTP/1.0 proxy
    3.5.21-25.1 lock rpm lock src
SUSE Linux Enterprise Server for SAP Applications 12.2 ppc64le
  • Packages
    squid
    A fully featured HTTP/1.0 proxy
    3.5.21-25.1 lock rpm lock src
SUSE Linux Enterprise Server 12.2 aarch64
  • Packages
    squid
    A fully featured HTTP/1.0 proxy
    3.5.21-25.1 lock rpm lock src
SUSE Linux Enterprise Server 12.2 s390x
  • Packages
    squid
    A fully featured HTTP/1.0 proxy
    3.5.21-25.1 lock rpm lock src