Mageia alert MGASA-2016-0095 (squid)
From: | Mageia Updates <buildsystem-daemon@mageia.org> | |
To: | updates-announce@ml.mageia.org | |
Subject: | [updates-announce] MGASA-2016-0095: Updated squid packages fix security vulnerabilities | |
Date: | Mon, 7 Mar 2016 12:20:52 +0100 | |
Message-ID: | <20160307112052.D7D879F6ED@duvel.mageia.org> |
MGASA-2016-0095 - Updated squid packages fix security vulnerabilities Publication date: 07 Mar 2016 URL: http://advisories.mageia.org/MGASA-2016-0095.html Type: security Affected Mageia releases: 5 CVE: CVE-2016-2569, CVE-2016-2570, CVE-2016-2571 Description: Updated squid packages fix security vulnerability: Due to incorrect bounds checking Squid is vulnerable to a denial of service attack when processing HTTP responses (CVE-2016-2569, CVE-2016-2570, CVE-2016-2571). References: - https://bugs.mageia.org/show_bug.cgi?id=17816 - http://www.squid-cache.org/Advisories/SQUID-2016_2.txt - http://openwall.com/lists/oss-security/2016/02/26/2 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2569 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2570 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2571 SRPMS: - 5/core/squid-3.4.13-1.4.mga5