Security update for squid
Announcement ID: | SUSE-SU-2021:1838-1 |
---|---|
Rating: | important |
References: | |
Cross-References: | |
CVSS scores: |
|
Affected Products: |
|
An update that solves five vulnerabilities and has three security fixes can now be installed.
Description:
This update for squid fixes the following issues:
- update to 4.15:
- CVE-2021-28652: Broken cache manager URL parsing (bsc#1185918)
- CVE-2021-28651: Memory leak in RFC 2169 response parsing (bsc#1185921)
- CVE-2021-28662: Limit HeaderLookupTable_t::lookup() to BadHdr and specific IDs (bsc#1185919)
- CVE-2021-31806: Handle more Range requests (bsc#1185916)
- CVE-2020-25097: HTTP Request Smuggling vulnerability (bsc#1183436)
- Handle more partial responses (bsc#1185923)
- fix previous change to reinstante permissions macros, because the wrong path has been used (bsc#1171569).
- use libexecdir instead of libdir to conform to recent changes in Factory (bsc#1171164).
- Reinstate permissions macros for pinger binary, because the permissions package is also responsible for setting up the cap_net_raw capability, currently a fresh squid install doesn't get a capability bit at all (bsc#1171569).
- Change pinger and basic_pam_auth helper to use standard permissions. pinger uses cap_net_raw=ep instead (bsc#1171569)
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
SUSE Linux Enterprise High Performance Computing 12 SP5
zypper in -t patch SUSE-SLE-SERVER-12-SP5-2021-1838=1
-
SUSE Linux Enterprise Server 12 SP5
zypper in -t patch SUSE-SLE-SERVER-12-SP5-2021-1838=1
-
SUSE Linux Enterprise Server for SAP Applications 12 SP5
zypper in -t patch SUSE-SLE-SERVER-12-SP5-2021-1838=1
Package List:
-
SUSE Linux Enterprise High Performance Computing 12 SP5 (aarch64 x86_64)
- squid-4.15-4.18.1
- squid-debugsource-4.15-4.18.1
- squid-debuginfo-4.15-4.18.1
-
SUSE Linux Enterprise Server 12 SP5 (aarch64 ppc64le s390x x86_64)
- squid-4.15-4.18.1
- squid-debugsource-4.15-4.18.1
- squid-debuginfo-4.15-4.18.1
-
SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64)
- squid-4.15-4.18.1
- squid-debugsource-4.15-4.18.1
- squid-debuginfo-4.15-4.18.1
References:
- https://www.suse.com/security/cve/CVE-2020-25097.html
- https://www.suse.com/security/cve/CVE-2021-28651.html
- https://www.suse.com/security/cve/CVE-2021-28652.html
- https://www.suse.com/security/cve/CVE-2021-28662.html
- https://www.suse.com/security/cve/CVE-2021-31806.html
- https://bugzilla.suse.com/show_bug.cgi?id=1171164
- https://bugzilla.suse.com/show_bug.cgi?id=1171569
- https://bugzilla.suse.com/show_bug.cgi?id=1183436
- https://bugzilla.suse.com/show_bug.cgi?id=1185916
- https://bugzilla.suse.com/show_bug.cgi?id=1185918
- https://bugzilla.suse.com/show_bug.cgi?id=1185919
- https://bugzilla.suse.com/show_bug.cgi?id=1185921
- https://bugzilla.suse.com/show_bug.cgi?id=1185923