Vulnerability Database
Blog
FAQ
Docs
SUSE-SU-2020:0661-1
See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:0661-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2020:0661-1
Related
CVE-2019-12523
CVE-2019-12526
CVE-2019-12528
CVE-2019-18676
CVE-2019-18677
CVE-2019-18678
CVE-2019-18679
CVE-2020-8449
CVE-2020-8450
CVE-2020-8517
Published
2020-03-12T16:01:37Z
Modified
2020-03-12T16:01:37Z
Summary
Security update for squid
Details
This update for squid fixes the following issues:
CVE-2019-12528: Fixed an information disclosure flaw in the FTP gateway (bsc#1162689).
CVE-2019-12526: Fixed potential remote code execution during URN processing (bsc#1156326).
CVE-2019-12523,CVE-2019-18676: Fixed multiple improper validations in URI processing (bsc#1156329).
CVE-2019-18677: Fixed Cross-Site Request Forgery in HTTP Request processing (bsc#1156328).
CVE-2019-18678: Fixed incorrect message parsing which could have led to HTTP request splitting issue (bsc#1156323).
CVE-2019-18679: Fixed information disclosure when processing HTTP Digest Authentication (bsc#1156324).
CVE-2020-8449: Fixed a buffer overflow when squid is acting as reverse-proxy (bsc#1162687).
CVE-2020-8450: Fixed a buffer overflow when squid is acting as reverse-proxy (bsc#1162687).
CVE-2020-8517: Fixed a buffer overflow in ext
lm
group_acl when processing NTLM Authentication credentials (bsc#1162691).
References
https://www.suse.com/support/update/announcement/2020/suse-su-20200661-1/
https://bugzilla.suse.com/1156323
https://bugzilla.suse.com/1156324
https://bugzilla.suse.com/1156326
https://bugzilla.suse.com/1156328
https://bugzilla.suse.com/1156329
https://bugzilla.suse.com/1162687
https://bugzilla.suse.com/1162689
https://bugzilla.suse.com/1162691
https://www.suse.com/security/cve/CVE-2019-12523
https://www.suse.com/security/cve/CVE-2019-12526
https://www.suse.com/security/cve/CVE-2019-12528
https://www.suse.com/security/cve/CVE-2019-18676
https://www.suse.com/security/cve/CVE-2019-18677
https://www.suse.com/security/cve/CVE-2019-18678
https://www.suse.com/security/cve/CVE-2019-18679
https://www.suse.com/security/cve/CVE-2020-8449
https://www.suse.com/security/cve/CVE-2020-8450
https://www.suse.com/security/cve/CVE-2020-8517
Affected packages
SUSE:HPE Helion OpenStack 8
/
squid
Package
Name
squid
Purl
purl:rpm/suse/squid&distro=HPE%20Helion%20OpenStack%208
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
3.5.21-26.20.1
Ecosystem specific
{ "binaries": [ { "squid": "3.5.21-26.20.1" } ] }
SUSE:OpenStack Cloud 7
/
squid
Package
Name
squid
Purl
purl:rpm/suse/squid&distro=SUSE%20OpenStack%20Cloud%207
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
3.5.21-26.20.1
Ecosystem specific
{ "binaries": [ { "squid": "3.5.21-26.20.1" } ] }
SUSE:OpenStack Cloud 8
/
squid
Package
Name
squid
Purl
purl:rpm/suse/squid&distro=SUSE%20OpenStack%20Cloud%208
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
3.5.21-26.20.1
Ecosystem specific
{ "binaries": [ { "squid": "3.5.21-26.20.1" } ] }
SUSE:OpenStack Cloud Crowbar 8
/
squid
Package
Name
squid
Purl
purl:rpm/suse/squid&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
3.5.21-26.20.1
Ecosystem specific
{ "binaries": [ { "squid": "3.5.21-26.20.1" } ] }
SUSE:Linux Enterprise Server for SAP Applications 12 SP2
/
squid
Package
Name
squid
Purl
purl:rpm/suse/squid&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
3.5.21-26.20.1
Ecosystem specific
{ "binaries": [ { "squid": "3.5.21-26.20.1" } ] }
SUSE:Linux Enterprise Server for SAP Applications 12 SP3
/
squid
Package
Name
squid
Purl
purl:rpm/suse/squid&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
3.5.21-26.20.1
Ecosystem specific
{ "binaries": [ { "squid": "3.5.21-26.20.1" } ] }
SUSE:Linux Enterprise Server 12 SP2-LTSS
/
squid
Package
Name
squid
Purl
purl:rpm/suse/squid&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSS
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
3.5.21-26.20.1
Ecosystem specific
{ "binaries": [ { "squid": "3.5.21-26.20.1" } ] }
SUSE:Linux Enterprise Server 12 SP2-BCL
/
squid
Package
Name
squid
Purl
purl:rpm/suse/squid&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCL
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
3.5.21-26.20.1
Ecosystem specific
{ "binaries": [ { "squid": "3.5.21-26.20.1" } ] }
SUSE:Linux Enterprise Server 12 SP3-LTSS
/
squid
Package
Name
squid
Purl
purl:rpm/suse/squid&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-LTSS
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
3.5.21-26.20.1
Ecosystem specific
{ "binaries": [ { "squid": "3.5.21-26.20.1" } ] }
SUSE:Linux Enterprise Server 12 SP3-BCL
/
squid
Package
Name
squid
Purl
purl:rpm/suse/squid&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCL
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
3.5.21-26.20.1
Ecosystem specific
{ "binaries": [ { "squid": "3.5.21-26.20.1" } ] }
SUSE:Linux Enterprise Server 12 SP4
/
squid
Package
Name
squid
Purl
purl:rpm/suse/squid&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
3.5.21-26.20.1
Ecosystem specific
{ "binaries": [ { "squid": "3.5.21-26.20.1" } ] }
SUSE:Linux Enterprise Server for SAP Applications 12 SP4
/
squid
Package
Name
squid
Purl
purl:rpm/suse/squid&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
3.5.21-26.20.1
Ecosystem specific
{ "binaries": [ { "squid": "3.5.21-26.20.1" } ] }
SUSE:Enterprise Storage 5
/
squid
Package
Name
squid
Purl
purl:rpm/suse/squid&distro=SUSE%20Enterprise%20Storage%205
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
3.5.21-26.20.1
Ecosystem specific
{ "binaries": [ { "squid": "3.5.21-26.20.1" } ] }
SUSE-SU-2020:0661-1 - OSV