MGASA-2021-0499

Source
https://advisories.mageia.org/MGASA-2021-0499.html
Import Source
https://advisories.mageia.org/MGASA-2021-0499.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2021-0499
Related
Published
2021-10-31T11:12:48Z
Modified
2021-10-31T10:46:12Z
Summary
Updated squid packages fix security vulnerability
Details

Updated squid packages fix security vulnerability:

Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure because of an out-of-bounds read in WCCP protocol data. This can be leveraged as part of a chain for remote code execution as nobody (CVE-2021-28116).

Squid is updated to 4.17 that fixes this issue and other bugs.

References
Credits

Affected packages