{"id":"MGASA-2016-0237","summary":"Updated squidguard packages fix security vulnerability","details":"The squidGuard.cgi program is vulnerable to a reflected cross site\nscripting vulnerability in the blocking script squidGuard.cgi. The\nvulnerability is triggered when a user clicks a link to a blocked site\nwhere the url has scripting instructions added (CVE-2015-8936).\n\nIn Mageia's squidguard package, both /var/www/cgi-bin/squidGuard.cgi and\n/usr/share/squidGuard-1.4/samples/squidGuard.cgi were affected.\n\nNote that it is highly recommended that any remaining users of this\npackage switch to ufdbguard, which has better compatibility with current\nversions of Squid.\n","modified":"2026-04-16T06:23:03.431349065Z","published":"2016-07-05T15:47:08Z","upstream":["CVE-2015-8936"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2016-0237.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=18757"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2016/06/21/5"},{"type":"WEB","url":"http://www.squidguard.org/Downloads/Patches/1.4/Readme.Patch-20150201"}],"affected":[{"package":{"name":"squidguard","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/squidguard?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.4-21.1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2016-0237.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}