Advisories ยป MGASA-2021-0499

Updated squid packages fix security vulnerability

Publication date: 31 Oct 2021
Modification date: 31 Oct 2021
Type: security
Affected Mageia releases : 8
CVE: CVE-2021-28116

Description

Updated squid packages fix security vulnerability:

Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows
information disclosure because of an out-of-bounds read in WCCP protocol
data. This can be leveraged as part of a chain for remote code execution
as nobody (CVE-2021-28116).

Squid is updated to 4.17 that fixes this issue and other bugs.
                

References

SRPMS

8/core