Login
Newsletter
Werbung

Sicherheit: Mehrere Probleme in Squid
Aktuelle Meldungen Distributionen
Name: Mehrere Probleme in Squid
ID: USN-5771-1
Distribution: Ubuntu
Plattformen: Ubuntu 16.04 ESM
Datum: Mo, 12. Dezember 2022, 07:11
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3948
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2569
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000027
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2570
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000024
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2571
Applikationen: Squid

Originalnachricht

--===============8615510571792349732==
Content-Type: multipart/signed; boundary="=-=-=";
micalg=pgp-sha512; protocol="application/pgp-signature"

--=-=-=
Content-Type: text/plain; charset=utf-
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-5771-1
December 12, 2022

squid3 regression
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 ESM

Summary:

USN-3557-1 introduced a regression in Squid.

Software Description:
- squid3: Web proxy cache server

Details:

USN-3557-1 fixed vulnerabilities in Squid. This update introduced a
regression which could cause the cache log to be filled with many Vary
loop messages. This update fixes the problem.

We apologize for the inconvenience.

Original advisory details:

Mathias Fischer discovered that Squid incorrectly handled certain long
strings in headers. A malicious remote server could possibly cause Squid to
crash, resulting in a denial of service. This issue was only addressed in
Ubuntu 16.04 LTS. (CVE-2016-2569)

William Lima discovered that Squid incorrectly handled XML parsing when
processing Edge Side Includes (ESI). A malicious remote server could
possibly cause Squid to crash, resulting in a denial of service. This issue
was only addressed in Ubuntu 16.04 LTS. (CVE-2016-2570)

Alex Rousskov discovered that Squid incorrectly handled response-parsing
failures. A malicious remote server could possibly cause Squid to crash,
resulting in a denial of service. This issue only applied to Ubuntu 16.04
LTS. (CVE-2016-2571)

Santiago Ruano Rincón discovered that Squid incorrectly handled certain
Vary headers. A remote attacker could possibly use this issue to cause
Squid to crash, resulting in a denial of service. This issue was only
addressed in Ubuntu 16.04 LTS. (CVE-2016-3948)

Louis Dion-Marcil discovered that Squid incorrectly handled certain Edge
Side Includes (ESI) responses. A malicious remote server could possibly
cause Squid to crash, resulting in a denial of service. (CVE-2018-1000024)

Louis Dion-Marcil discovered that Squid incorrectly handled certain Edge
Side Includes (ESI) responses. A malicious remote server could possibly
cause Squid to crash, resulting in a denial of service. (CVE-2018-1000027)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 ESM:
squid 3.5.12-1ubuntu7.16+esm1

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-5771-1
https://launchpad.net/bugs/1999346

--=-=-
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQFOBAEBCgA4FiEEiOlTC8vdwgBRe16w9JjS2d59rZwFAmOWmy8aHGFsZXgubXVy
cmF5QGNhbm9uaWNhbC5jb20ACgkQ9JjS2d59rZypdwgAlrlVBMmenBB4hhteHsmH
0rzeH+2axlR+L81OTOOJAwMNWm2nruAaihR0MCou4Xn/2Spgh4xMYWz46QQ4zexp
nyP3oZic195tftMyEYjHxcWlPtRbCBISEcJvZXIMLE11jn7ksnIUbzXjbX5SjTMR
a/Iw6I26n+t+QiLp9doTPBsCeK2JHTr4/yZI/BreJeHWAlWU12SI9jCuRCHXcjqZ
oJKCoUM6/BfVDqIWLWLWUwd9qvqw2oOFy7wf8UU72ChHpTDHUjbijEiDceWUr7jJ
AlyCJBDAFOnULzKheLvdZ0qK2568QPWSHMlymclT0+32+5YXXt0mM6pJUQuTtm7c
Uw==
=tKOl
-----END PGP SIGNATURE-----
--=-=-=--


--===============8615510571792349732==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

Cg==

--===============8615510571792349732==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung