Login
Newsletter
Werbung

Sicherheit: Mehrere Probleme in Squid (Aktualisierung)
Aktuelle Meldungen Distributionen
Name: Mehrere Probleme in Squid (Aktualisierung)
ID: USN-4446-2
Distribution: Ubuntu
Plattformen: Ubuntu 16.04 LTS, Ubuntu 18.04 LTS
Datum: Do, 27. August 2020, 23:49
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12524
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18676
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12523
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12520
Applikationen: Squid
Update von: Mehrere Probleme in Squid

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============5671125650286397249==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="kDMMC9Xn8zoC7nkRnJoTtlQBhk8DNjty9"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--kDMMC9Xn8zoC7nkRnJoTtlQBhk8DNjty9
Content-Type: multipart/mixed;
boundary="MEGoJ99e4mSfTOBCa5wwcbR9pqbx9XaZs"

--MEGoJ99e4mSfTOBCa5wwcbR9pqbx9XaZs
Content-Type: text/plain; charset=utf-8
Content-Language: en-C
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-4446-2
August 27, 2020

squid3 regression
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

USN-4446-1 introduced a regression in Squid.

Software Description:
- squid3: Web proxy cache server

Details:

USN-4446-1 fixed vulnerabilities in Squid. The update introduced a
regression when using Squid with the icap or ecap protocols. This update
fixes the problem.

We apologize for the inconvenience.

Original advisory details:

Jeriko One discovered that Squid incorrectly handled caching certain
requests. A remote attacker could possibly use this issue to perform
cache-injection attacks or gain access to reverse proxy features such as
ESI. (CVE-2019-12520)
Jeriko One and Kristoffer Danielsson discovered that Squid incorrectly
handled certain URN requests. A remote attacker could possibly use this
issue to bypass access checks. (CVE-2019-12523)
Jeriko One discovered that Squid incorrectly handled URL decoding. A remote
attacker could possibly use this issue to bypass certain rule checks.
(CVE-2019-12524)
Jeriko One and Kristoffer Danielsson discovered that Squid incorrectly
handled input validation. A remote attacker could use this issue to cause
Squid to crash, resulting in a denial of service. (CVE-2019-18676)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
squid 3.5.27-1ubuntu1.8

Ubuntu 16.04 LTS:
squid 3.5.12-1ubuntu7.13

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4446-2
https://usn.ubuntu.com/4446-1
https://launchpad.net/bugs/1890265

Package Information:
https://launchpad.net/ubuntu/+source/squid3/3.5.27-1ubuntu1.8
https://launchpad.net/ubuntu/+source/squid3/3.5.12-1ubuntu7.13


--MEGoJ99e4mSfTOBCa5wwcbR9pqbx9XaZs--

--kDMMC9Xn8zoC7nkRnJoTtlQBhk8DNjty9
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAl9HqbcACgkQZWnYVadE
vpP6gRAAhdKcUVo73pdNSyntCRPxTV0mtWpXZ7ZJ0CLS7s6wpomUmFF4dURLZy8K
nD74+a48b0uKAovvsGAaUhQCbf+0yux8LW7s/mQJkFautwBP2xsDObzusH3lRmmd
b/iFIWCqpBnwWGkvw9TT0q/JQLm9vhnd5sr9Qm+HK/+KD3i2INADYqssaOK1+q6R
r4WcQKppsBe+q/DZafHDVti6wjX9clPWGBk7z0N8g/TRL3JotEZ6f6BbAPnq/Z3V
ByhPKrwu0WiBrx04WcGa7uQw8jtMqWMKmpsg86RNdrqqcHeSjhM0uMiXns93z3zY
1wYeWykFzCESTkg4lv2LAG7V9xMgzVmhHbklt3ooOdDKjS9NG25vJ310w1T6a8rj
2jOnxPy5R8R8yEMu+9/4e1yNri+qOMnJP+QYYeTNcrPqJAQh/K+QVcophjgPm1Qm
iFJ6NdhVODbcCM5Ag2lWJNBoeDmQKVRy0rz/QLLVLwjgS4wTyofEg4oYEAtY0xye
iMjlJw7UndT58Mv8Ir0u9JiO981GMNLDnnwl+a/kayteav4wxYQQydFW7YRd3qae
5SJMG2mA8p74Ja75v0s/I/s3PsEDtiv+yIytlq178tQgzjmWRfuaXTI84lloaaRd
UoP2Pu40r6P17sDWIRdJfG1QfH91b4eYACsTFsJpOJEs/zBJdEc=
=7NTI
-----END PGP SIGNATURE-----

--kDMMC9Xn8zoC7nkRnJoTtlQBhk8DNjty9--


--===============5671125650286397249==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

LS0gCnVidW50dS1zZWN1cml0eS1hbm5vdW5jZSBtYWlsaW5nIGxpc3QKdWJ1bnR1LXNlY3VyaXR5
LWFubm91bmNlQGxpc3RzLnVidW50dS5jb20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJl
IGF0OiBodHRwczovL2xpc3RzLnVidW50dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtc2Vj
dXJpdHktYW5ub3VuY2UK

--===============5671125650286397249==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung