MGASA-2019-0265

Source
https://advisories.mageia.org/MGASA-2019-0265.html
Import Source
https://advisories.mageia.org/MGASA-2019-0265.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2019-0265
Related
Published
2019-09-12T19:09:52Z
Modified
2019-09-12T18:17:37Z
Summary
Updated squid packages fix security vulnerabilities
Details

Updated squid packages fix security vulnerabilities:

It was discovered that Squid incorrectly handled Digest authentication. A remote attacker could possibly use this issue to cause Squid to crash, resulting in a denial of service (CVE-2019-12525).

It was discovered that Squid incorrectly handled Basic authentication. A remote attacker could possibly use this issue to cause Squid to crash, resulting in a denial of service (CVE-2019-12529).

It was discovered that Squid incorrectly handled the cachemgr.cgi web module. A remote attacker could possibly use this issue to conduct cross-site scripting (XSS) attacks (CVE-2019-13345).

References
Credits

Affected packages

Mageia:6 / squid

Package

Name
squid
Purl
pkg:rpm/mageia/squid?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.5.27-1.2.mga6

Ecosystem specific

{
    "section": "core"
}