MGASA-2024-0126

Source
https://advisories.mageia.org/MGASA-2024-0126.html
Import Source
https://advisories.mageia.org/MGASA-2024-0126.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2024-0126
Related
Published
2024-04-12T20:45:19Z
Modified
2024-04-12T20:32:09Z
Summary
Updated squid packages fix security vulnerabilities
Details

Affected versions of squid are subject to a a Use-After-Free bug which can lead to a Denial of Service attack via collapsed forwarding. All versions of Squid from 3.5 up to and including 5.9 configured with "collapsedforwarding on" are vulnerable. Configurations with "collapsedforwarding off" or without a "collapsed_forwarding" directive are not vulnerable. (CVE-2023-49288) Squid is vulnerable to Denial of Service attack against HTTP and HTTPS clients due to an Improper Handling of Structural Elements bug. (CVE-2023-5824)

References
Credits

Affected packages