Squid is a high-performance proxy caching server. It handles all requests in a single, non-blocking, I/O-driven process and keeps meta data and implements negative caching of failed requests.\r\n\r\n Security Fix(es):\r\n\r\n An issue was discovered in Squid through 4.7. When handling the tag esi:when when ESI is enabled, Squid calls ESIExpression::Evaluate. This function uses a fixed stack buffer to hold the expression while its being evaluated. When processing the expression, it could either evaluate the top of the stack, or add a new member to the stack. When adding a new member, there is no check to ensure that the stack wont overflow.(CVE-2019-12519)\r\n\r\n
{
"severity": "Critical"
}{
"x86_64": [
"squid-4.9-3.oe1.x86_64.rpm",
"squid-debuginfo-4.9-3.oe1.x86_64.rpm",
"squid-debugsource-4.9-3.oe1.x86_64.rpm",
"squid-4.9-3.oe1.x86_64.rpm",
"squid-debuginfo-4.9-3.oe1.x86_64.rpm",
"squid-debugsource-4.9-3.oe1.x86_64.rpm"
],
"src": [
"squid-4.9-3.oe1.src.rpm",
"squid-4.9-3.oe1.src.rpm"
],
"aarch64": [
"squid-4.9-3.oe1.aarch64.rpm",
"squid-debuginfo-4.9-3.oe1.aarch64.rpm",
"squid-debugsource-4.9-3.oe1.aarch64.rpm",
"squid-4.9-3.oe1.aarch64.rpm",
"squid-debuginfo-4.9-3.oe1.aarch64.rpm",
"squid-debugsource-4.9-3.oe1.aarch64.rpm"
]
}
{
"x86_64": [
"squid-4.9-3.oe1.x86_64.rpm",
"squid-debuginfo-4.9-3.oe1.x86_64.rpm",
"squid-debugsource-4.9-3.oe1.x86_64.rpm"
],
"src": [
"squid-4.9-3.oe1.src.rpm"
],
"aarch64": [
"squid-4.9-3.oe1.aarch64.rpm",
"squid-debuginfo-4.9-3.oe1.aarch64.rpm",
"squid-debugsource-4.9-3.oe1.aarch64.rpm"
]
}