Release Info

Advisory: CLSA-2021:1634925600

OS: Oracle Linux 6 ELS

Public date: 2021-10-22 00:00:00

Project: squid

Version: 3.1.23-30.el6.cloudlinux.els

Errata link: https://errata.cloudlinux.com/ol6/CLSA-2021-1634925600.html

Changelog

- CVE-2020-14058: fix handling of unknown SSL errors which resulted in denial of service - CVE-2020-15049: fix incorrect validation of Content-Length field leading to Http smuggling and Poisoning attack

Update

Packages list

squid-3.1.23-30.el6.cloudlinux.els.x86_64.rpm

CVEs

CVE-2020-15049
CVE-2020-14058