• [SECURITY] [DSA 4732-1] squid security update

    From Moritz Muehlenhoff@1:229/2 to All on Tue Jul 21 21:10:01 2020
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-4732-1 [email protected] https://www.debian.org/security/ Moritz Muehlenhoff
    July 21, 2020 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : squid
    CVE ID : CVE-2019-18860 CVE-2020-1504

    Two security issues were discovered in the Squid proxy caching
    server, which could result in cache poisoning, request smuggling
    and incomplete validation of hostnames in cachemgr.cgi.

    For the stable distribution (buster), these problems have been fixed in
    version 4.6-1+deb10u3.

    We recommend that you upgrade your squid packages.

    For the detailed security status of squid please refer to
    its security tracker page at:
    https://security-tracker.debian.org/tracker/squid

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAl8XPJoACgkQEMKTtsN8 TjbP9xAAvcVYW/X4/ARDe5ALpczrKbKEC2QAxgniuY/rPE4b33bFmkYrmivZWuNW UazQpnFw47SFRKMUsuJeZEeDOp29RD5oBCVYX+syqVdWfITbUfLr6/5M1VFI9Ek8 Wg5iDB777dpWOBlHf9P4yE4eX/jEjY7F/6bniGPFlWJ6K/j5nKYWs5T1btyeBTgu AS22H957frUbVrMC0dqPwWB9VwE1c0p+DEX+j5B7rKG/MOouJO2fu4lPU+aEvVLt JalosVMcpM5akP7phCu3BiJftlBpAtftz5P/dPdNs+sbiuHpCjt3nWT4kDL0IDJZ UOhplMtzTIMPB+wcApYEooGwbQsV4FR6P+29evIMPnhA7M/UayveZ/YIhSXclRqX vc6ZymrOucxTf5cEWu6oaZmB4lxK9KL9hO5dlFB7uMGr/CXu7nwqs+jeZpzbmXLS DmHhje4sslvPt9pUh0NHB+N2qB2LteLUo/uORUgQ12UbMC5yHa0ZlFIXbwdOcNHO egzH/asPPJL+b0qX7qBE66Z6u/yulDhWA8A46fr3+p3pCgXiLrVha/r+NJx7joIf Pszz6ngOXdHCskWPmAvjgZggIHmRsvcK+eGUzq0R6V3jYTw9BJAfOQoJCPnvTutJ ZebCdviDgAz1w8hztVS5aq4iDWrLAp/W7nU9Lx/vdZNA/2+hcq0=
    =2mJg
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)