2020年9月26日 星期六

[USN-4477-1] Squid vulnerabilities

 ---------- Forwarded message ---------

From: Marc Deslauriers <marc.deslauriers@canonical.com>

Date: Aug 28, 2020 2:17AM

Amit Klein discovered that Squid incorrectly validated certain data. A

remote attacker could possibly use this issue to perform an HTTP request

smuggling attack, resulting in cache poisoning. (CVE-2020-15810)

Régis Leroy discovered that Squid incorrectly validated certain data. A

remote attacker could possibly use this issue to perform an HTTP request

splitting attack, resulting in cache poisoning. (CVE-2020-15811)

Lubos Uhliarik discovered that Squid incorrectly handled certain Cache

Digest response messages sent by trusted peers. A remote attacker could

possibly use this issue to cause Squid to consume resources, resulting in a

denial of service. (CVE-2020-24606)

References:

  https://usn.ubuntu.com/4477-1

  CVE-2020-15810, CVE-2020-15811, CVE-2020-24606

沒有留言:

張貼留言