{"id":"MGASA-2021-0237","summary":"Updated squid packages fix security vulnerabilities","details":"Updated squid packages fix security vulnerabilities:\n\nDue to improper input validation Squid is vulnerable to an HTTP Request\nSmuggling attack. This problem allows a trusted client to perform HTTP\nRequest Smuggling and access services otherwise forbidden by Squid\nsecurity controls (CVE-2020-25097).\n\nJoshua Rogers discovered that Squid incorrectly handled requests with the\nurn: scheme. A remote attacker could possibly use this issue to causeSquid\nto consume resources, leading to a denial of service (CVE-2021-28651).\n\nJoshua Rogers discovered that Squid incorrectly handled requests to the Cache\nManager API. A remote attacker with access privileges could possibly use this\nissue to cause Squid to consume resources, leading to a denial of service\n(CVE-2021-28652).\n\nJoshua Rogers discovered that Squid incorrectly handled certain response\nheaders. A remote attacker could possibly use this issue to cause Squid to\ncrash, resulting in a denial of service (CVE-2021-28662).\n\nJoshua Rogers discovered that Squid incorrectly handled range request\nprocessing. A remote attacker could possibly use this issue to cause Squid to\ncrash, resulting in a denial of service (CVE-2021-31806, CVE-2021-31807,\nCVE-2021-31808).\n\nJoshua Rogers discovered that Squid incorrectly handled certain HTTP\nresponses. A remote attacker could possibly use this issue to cause Squid to\ncrash, resulting in a denial of service (CVE-2021-33620).\n\nThe squid package has been updated to version 4.15, fixing theese issues and\nother bugs.\n","modified":"2026-04-16T04:42:50.616141523Z","published":"2021-06-08T16:46:03Z","upstream":["CVE-2020-25097","CVE-2021-28651","CVE-2021-28652","CVE-2021-28662","CVE-2021-31806","CVE-2021-31807","CVE-2021-31808","CVE-2021-33620"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2021-0237.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=28799"},{"type":"ADVISORY","url":"https://github.com/squid-cache/squid/security/advisories/GHSA-jvf6-h9gj-pmj6"},{"type":"ADVISORY","url":"https://github.com/squid-cache/squid/security/advisories/GHSA-ch36-9jhx-phm4"},{"type":"ADVISORY","url":"https://github.com/squid-cache/squid/security/advisories/GHSA-m47m-9hvw-7447"},{"type":"ADVISORY","url":"https://github.com/squid-cache/squid/security/advisories/GHSA-jjq6-mh2h-g39h"},{"type":"ADVISORY","url":"https://github.com/squid-cache/squid/security/advisories/GHSA-pxwq-f3qr-w2xf"},{"type":"ADVISORY","url":"https://github.com/squid-cache/squid/security/advisories/GHSA-572g-rvwr-6c7f"},{"type":"WEB","url":"https://github.com/squid-cache/squid/commit/fa47a3bc4d382e28e7235d08750401b910e4b13a"},{"type":"WEB","url":"https://github.com/squid-cache/squid/commit/648729b05673c6166c5d91c6ee4cda30cc164839"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2021:1135"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-4981-1"}],"affected":[{"package":{"name":"squid","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/squid?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.15-1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2021-0237.json"}},{"package":{"name":"squid","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/squid?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.15-1.mga8"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2021-0237.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}