MGASA-2016-0237

Source
https://advisories.mageia.org/MGASA-2016-0237.html
Import Source
https://advisories.mageia.org/MGASA-2016-0237.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2016-0237
Related
Published
2016-07-05T15:47:08Z
Modified
2016-07-05T15:37:01Z
Summary
Updated squidguard packages fix security vulnerability
Details

The squidGuard.cgi program is vulnerable to a reflected cross site scripting vulnerability in the blocking script squidGuard.cgi. The vulnerability is triggered when a user clicks a link to a blocked site where the url has scripting instructions added (CVE-2015-8936).

In Mageia's squidguard package, both /var/www/cgi-bin/squidGuard.cgi and /usr/share/squidGuard-1.4/samples/squidGuard.cgi were affected.

Note that it is highly recommended that any remaining users of this package switch to ufdbguard, which has better compatibility with current versions of Squid.

References
Credits

Affected packages

Mageia:5 / squidguard

Package

Name
squidguard
Purl
pkg:rpm/mageia/squidguard?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4-21.1.mga5

Ecosystem specific

{
    "section": "core"
}