ALT-BU-2017-3117-1
Branch c7 update bulletin.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2016-10002
Incorrect processing of responses to If-None-Modified HTTP conditional requests in Squid HTTP Proxy 3.1.10 through 3.1.23, 3.2.0.3 through 3.5.22, and 4.0.1 through 4.0.16 leads to client-specific Cookie data being leaked to other clients. Attack requests can easily be crafted by a client to probe a cache for this information.
- RHSA-2017:0182
- RHSA-2017:0182
- RHSA-2017:0183
- RHSA-2017:0183
- DSA-3745
- DSA-3745
- [oss-security] 20161217 Re: CVE Request - squid HTTP proxy multiple Information Disclosure issues
- [oss-security] 20161217 Re: CVE Request - squid HTTP proxy multiple Information Disclosure issues
- 94953
- 94953
- 1037513
- 1037513
- http://www.squid-cache.org/Advisories/SQUID-2016_11.txt
- http://www.squid-cache.org/Advisories/SQUID-2016_11.txt
Modified: 2024-11-21
CVE-2016-10003
Incorrect HTTP Request header comparison in Squid HTTP Proxy 3.5.0.1 through 3.5.22, and 4.0.1 through 4.0.16 results in Collapsed Forwarding feature mistakenly identifying some private responses as being suitable for delivery to multiple clients.
- [oss-security] 20161217 Re: CVE Request - squid HTTP proxy multiple Information Disclosure issues
- [oss-security] 20161217 Re: CVE Request - squid HTTP proxy multiple Information Disclosure issues
- 94953
- 94953
- 1037512
- 1037512
- http://www.squid-cache.org/Advisories/SQUID-2016_10.txt
- http://www.squid-cache.org/Advisories/SQUID-2016_10.txt
Package kernel-image-std-def updated to version 3.14.59-alt1.M70C.8 for branch c7 in task 182978.
Closed vulnerabilities
BDU:2017-01162
Уязвимость реализации серверов NFSv2 и NFSv3 в ядре операционной системы Linux, позволяющая нарушителю вызвать ошибки арифметических указателей или оказать другое воздействие
Modified: 2024-11-21
CVE-2017-7895
The NFSv2 and NFSv3 server implementations in the Linux kernel through 4.10.13 lack certain checks for the end of a buffer, which allows remote attackers to trigger pointer-arithmetic errors or possibly have unspecified other impact via crafted requests, related to fs/nfsd/nfs3xdr.c and fs/nfsd/nfsxdr.c.
- DSA-3886
- DSA-3886
- 98085
- 98085
- RHSA-2017:1615
- RHSA-2017:1615
- RHSA-2017:1616
- RHSA-2017:1616
- RHSA-2017:1647
- RHSA-2017:1647
- RHSA-2017:1715
- RHSA-2017:1715
- RHSA-2017:1723
- RHSA-2017:1723
- RHSA-2017:1766
- RHSA-2017:1766
- RHSA-2017:1798
- RHSA-2017:1798
- RHSA-2017:2412
- RHSA-2017:2412
- RHSA-2017:2428
- RHSA-2017:2428
- RHSA-2017:2429
- RHSA-2017:2429
- RHSA-2017:2472
- RHSA-2017:2472
- RHSA-2017:2732
- RHSA-2017:2732
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=13bf9fbff0e5e099e2b6f003a0ab8ae145436309
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=13bf9fbff0e5e099e2b6f003a0ab8ae145436309
- https://github.com/torvalds/linux/commit/13bf9fbff0e5e099e2b6f003a0ab8ae145436309
- https://github.com/torvalds/linux/commit/13bf9fbff0e5e099e2b6f003a0ab8ae145436309