ALT-BU-2020-4111-1
Branch p9 update bulletin.
Package firefox-esr updated to version 78.4.0-alt0.1.p9 for branch p9 in task 260258.
Closed vulnerabilities
BDU:2021-01486
Уязвимость реализации технологии WebRTC программных средств Google Chrome, Firefox, Firefox-ESR и Thunderbird, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2022-05797
Уязвимость браузеров Mozilla Firefox, Mozilla Firefox ESR и почтового клиента Thunderbird, связанная с копированием буфера без проверки размера входных данных, позволяющая нарушителю выполнить произвольный код
Modified: 2024-11-21
CVE-2020-15683
Mozilla developers and community members reported memory safety bugs present in Firefox 81 and Firefox ESR 78.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 78.4, Firefox < 82, and Thunderbird < 78.4.
- openSUSE-SU-2020:1732
- openSUSE-SU-2020:1732
- openSUSE-SU-2020:1748
- openSUSE-SU-2020:1748
- openSUSE-SU-2020:1780
- openSUSE-SU-2020:1780
- openSUSE-SU-2020:1785
- openSUSE-SU-2020:1785
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=1576843%2C1656987%2C1660954%2C1662760%2C1663439%2C1666140
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=1576843%2C1656987%2C1660954%2C1662760%2C1663439%2C1666140
- [debian-lts-announce] 20201027 [SECURITY] [DLA 2416-1] thunderbird security update
- [debian-lts-announce] 20201027 [SECURITY] [DLA 2416-1] thunderbird security update
- GLSA-202010-08
- GLSA-202010-08
- DSA-4780
- DSA-4780
- https://www.mozilla.org/security/advisories/mfsa2020-45/
- https://www.mozilla.org/security/advisories/mfsa2020-45/
- https://www.mozilla.org/security/advisories/mfsa2020-46/
- https://www.mozilla.org/security/advisories/mfsa2020-46/
- https://www.mozilla.org/security/advisories/mfsa2020-47/
- https://www.mozilla.org/security/advisories/mfsa2020-47/
Modified: 2024-11-21
CVE-2020-15969
Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- openSUSE-SU-2020:1829
- openSUSE-SU-2020:1829
- 20201215 APPLE-SA-2020-12-14-1 iOS 14.3 and iPadOS 14.3
- 20201215 APPLE-SA-2020-12-14-1 iOS 14.3 and iPadOS 14.3
- 20201215 APPLE-SA-2020-12-14-3 macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave
- 20201215 APPLE-SA-2020-12-14-3 macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave
- 20201215 APPLE-SA-2020-12-14-5 watchOS 7.2
- 20201215 APPLE-SA-2020-12-14-5 watchOS 7.2
- 20201215 APPLE-SA-2020-12-14-7 tvOS 14.3
- 20201215 APPLE-SA-2020-12-14-7 tvOS 14.3
- 20201215 APPLE-SA-2020-12-14-8 Safari 14.0.2
- 20201215 APPLE-SA-2020-12-14-8 Safari 14.0.2
- https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html
- https://crbug.com/1124659
- https://crbug.com/1124659
- FEDORA-2020-8aca25b5c8
- FEDORA-2020-8aca25b5c8
- FEDORA-2020-127d40f1ab
- FEDORA-2020-127d40f1ab
- FEDORA-2020-4e8e48da22
- FEDORA-2020-4e8e48da22
- GLSA-202101-30
- GLSA-202101-30
- https://support.apple.com/kb/HT212003
- https://support.apple.com/kb/HT212003
- https://support.apple.com/kb/HT212005
- https://support.apple.com/kb/HT212005
- https://support.apple.com/kb/HT212007
- https://support.apple.com/kb/HT212007
- https://support.apple.com/kb/HT212009
- https://support.apple.com/kb/HT212009
- https://support.apple.com/kb/HT212011
- https://support.apple.com/kb/HT212011
- DSA-4824
- DSA-4824
Package wpa_supplicant updated to version 2.9-alt3 for branch p9 in task 260257.
Closed vulnerabilities
BDU:2019-04775
Уязвимость компонента защищённого доступа Wi-Fi WPA Supplicant, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2019-16275
hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service that should have been prevented by PMF (aka management frame protection). The attacker must send a crafted 802.11 frame from a location that is within the 802.11 communications range.
- [oss-security] 20190912 Re: hostapd/wpa_supplicant: AP mode PMF disconnection protection bypass
- [oss-security] 20190912 Re: hostapd/wpa_supplicant: AP mode PMF disconnection protection bypass
- [debian-lts-announce] 20190916 [SECURITY] [DLA 1922-1] wpa security update
- [debian-lts-announce] 20190916 [SECURITY] [DLA 1922-1] wpa security update
- FEDORA-2019-0e0b28001d
- FEDORA-2019-0e0b28001d
- FEDORA-2019-65509aac53
- FEDORA-2019-65509aac53
- FEDORA-2019-740834c559
- FEDORA-2019-740834c559
- FEDORA-2019-2bdcccee3c
- FEDORA-2019-2bdcccee3c
- FEDORA-2019-2265b5ae86
- FEDORA-2019-2265b5ae86
- 20190929 [SECURITY] [DSA 4538-1] wpa security update
- 20190929 [SECURITY] [DSA 4538-1] wpa security update
- USN-4136-1
- USN-4136-1
- USN-4136-2
- USN-4136-2
- https://w1.fi/security/2019-7/
- https://w1.fi/security/2019-7/
- https://w1.fi/security/2019-7/ap-mode-pmf-disconnection-protection-bypass.txt
- https://w1.fi/security/2019-7/ap-mode-pmf-disconnection-protection-bypass.txt
- DSA-4538
- DSA-4538
- https://www.openwall.com/lists/oss-security/2019/09/11/7
- https://www.openwall.com/lists/oss-security/2019/09/11/7
Closed bugs
Closed vulnerabilities
BDU:2019-01946
Уязвимость реализации протокола EAP-PWD сертификации устройств беспроводной связи WPA, связанная с использованием криптографических алгоритмов, содержащих дефекты, позволяющая нарушителю осуществить установку и запуск приложений или получить доступ к конфиденциальным данным
BDU:2019-01947
Уязвимость компонента wpa_supplicant протокола EAP-PWD сертификации устройств беспроводной связи WPA, связанная с неправильной аутентификацией, позволяющая нарушителю оказать воздействие на целостность и конфиденциальность данных, а также вызвать отказ в обслуживании
BDU:2019-01948
Уязвимость компонента EAP Server протокола EAP-PWD сертификации устройств беспроводной связи WPA, связанная с некорректным использованием привилегий, позволяющая нарушителю оказать воздействие на целостность и конфиденциальность данных или вызвать отказ в обслуживании
BDU:2019-01949
Уязвимость компонента wpa_supplicant протокола EAP-PWD сертификации устройств беспроводной связи WPA, связанная с некорректным использованием привилегий, позволяющая нарушителю оказать воздействие на целостность и конфиденциальность данных или вызвать отказ в обслуживании
BDU:2019-04775
Уязвимость компонента защищённого доступа Wi-Fi WPA Supplicant, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2020-00775
Уязвимость функции wpa_supplicant сервера EAP hostapd, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2020-03318
Уязвимость реализации протокола WPA программы-демона пользовательского пространства hostapd, позволяющая нарушителю получить учетные данные
BDU:2021-05846
Уязвимость реализации SAE функции wpa_supplicant сертификации устройств беспроводной связи WPA, связанная с раскрытием информации, позволяющая нарушителю получить доступ к конфиденциальным данным
BDU:2021-05847
Уязвимость реализации SAE функции wpa_supplicant сертификации устройств беспроводной связи WPA, связанная с недостатками процедуры аутентификации, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2019-11555
The EAP-pwd implementation in hostapd (EAP server) before 2.8 and wpa_supplicant (EAP peer) before 2.8 does not validate fragmentation reassembly state properly for a case where an unexpected fragment could be received. This could result in process termination due to a NULL pointer dereference (denial of service). This affects eap_server/eap_server_pwd.c and eap_peer/eap_pwd.c.
- [oss-security] 20190426 Re: wpa_supplicant/hostapd: EAP-pwd message reassembly issue with unexpected fragment
- [oss-security] 20190426 Re: wpa_supplicant/hostapd: EAP-pwd message reassembly issue with unexpected fragment
- [debian-lts-announce] 20190731 [SECURITY] [DLA 1867-1] wpa security update
- [debian-lts-announce] 20190731 [SECURITY] [DLA 1867-1] wpa security update
- FEDORA-2019-ff1b728d09
- FEDORA-2019-ff1b728d09
- FEDORA-2019-d6bc3771a4
- FEDORA-2019-d6bc3771a4
- FEDORA-2019-28d3ca93d2
- FEDORA-2019-28d3ca93d2
- 20190515 FreeBSD Security Advisory FreeBSD-SA-19:03.wpa
- 20190515 FreeBSD Security Advisory FreeBSD-SA-19:03.wpa
- 20190527 [SECURITY] [DSA 4450-1] wpa security update
- 20190527 [SECURITY] [DSA 4450-1] wpa security update
- FreeBSD-SA-19:03
- FreeBSD-SA-19:03
- GLSA-201908-25
- GLSA-201908-25
- USN-3969-1
- USN-3969-1
- USN-3969-2
- USN-3969-2
- https://w1.fi/security/2019-5/
- https://w1.fi/security/2019-5/
- https://w1.fi/security/2019-5/eap-pwd-message-reassembly-issue-with-unexpected-fragment.txt
- https://w1.fi/security/2019-5/eap-pwd-message-reassembly-issue-with-unexpected-fragment.txt
- DSA-4450
- DSA-4450
- https://www.openwall.com/lists/oss-security/2019/04/18/6
- https://www.openwall.com/lists/oss-security/2019/04/18/6
Modified: 2024-11-21
CVE-2019-13377
The implementations of SAE and EAP-pwd in hostapd and wpa_supplicant 2.x through 2.8 are vulnerable to side-channel attacks as a result of observable timing differences and cache access patterns when Brainpool curves are used. An attacker may be able to gain leaked information from a side-channel attack that can be used for full password recovery.
- FEDORA-2019-97e9040197
- FEDORA-2019-97e9040197
- 20190929 [SECURITY] [DSA 4538-1] wpa security update
- 20190929 [SECURITY] [DSA 4538-1] wpa security update
- https://usn.ubuntu.com/4098-1/
- https://usn.ubuntu.com/4098-1/
- https://w1.fi/cgit/hostap/commit/?id=147bf7b88a9c231322b5b574263071ca6dbb0503
- https://w1.fi/cgit/hostap/commit/?id=147bf7b88a9c231322b5b574263071ca6dbb0503
- https://w1.fi/cgit/hostap/commit/?id=cd803299ca485eb857e37c88f973fccfbb8600e5
- https://w1.fi/cgit/hostap/commit/?id=cd803299ca485eb857e37c88f973fccfbb8600e5
- DSA-4538
- DSA-4538
Modified: 2024-11-21
CVE-2019-16275
hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service that should have been prevented by PMF (aka management frame protection). The attacker must send a crafted 802.11 frame from a location that is within the 802.11 communications range.
- [oss-security] 20190912 Re: hostapd/wpa_supplicant: AP mode PMF disconnection protection bypass
- [oss-security] 20190912 Re: hostapd/wpa_supplicant: AP mode PMF disconnection protection bypass
- [debian-lts-announce] 20190916 [SECURITY] [DLA 1922-1] wpa security update
- [debian-lts-announce] 20190916 [SECURITY] [DLA 1922-1] wpa security update
- FEDORA-2019-0e0b28001d
- FEDORA-2019-0e0b28001d
- FEDORA-2019-65509aac53
- FEDORA-2019-65509aac53
- FEDORA-2019-740834c559
- FEDORA-2019-740834c559
- FEDORA-2019-2bdcccee3c
- FEDORA-2019-2bdcccee3c
- FEDORA-2019-2265b5ae86
- FEDORA-2019-2265b5ae86
- 20190929 [SECURITY] [DSA 4538-1] wpa security update
- 20190929 [SECURITY] [DSA 4538-1] wpa security update
- USN-4136-1
- USN-4136-1
- USN-4136-2
- USN-4136-2
- https://w1.fi/security/2019-7/
- https://w1.fi/security/2019-7/
- https://w1.fi/security/2019-7/ap-mode-pmf-disconnection-protection-bypass.txt
- https://w1.fi/security/2019-7/ap-mode-pmf-disconnection-protection-bypass.txt
- DSA-4538
- DSA-4538
- https://www.openwall.com/lists/oss-security/2019/09/11/7
- https://www.openwall.com/lists/oss-security/2019/09/11/7
Modified: 2024-11-21
CVE-2019-9494
The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. An attacker may be able to gain leaked information from a side channel attack that can be used for full password recovery. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.7 are affected.
- openSUSE-SU-2020:0222
- http://packetstormsecurity.com/files/152914/FreeBSD-Security-Advisory-FreeBSD-SA-19-03.wpa.html
- FEDORA-2019-d03bae77f5
- FEDORA-2019-eba1109acd
- FEDORA-2019-f409af9fbe
- 20190515 FreeBSD Security Advisory FreeBSD-SA-19:03.wpa
- FreeBSD-SA-19:03
- https://w1.fi/security/2019-1/
- https://www.synology.com/security/advisory/Synology_SA_19_16
- openSUSE-SU-2020:0222
- https://www.synology.com/security/advisory/Synology_SA_19_16
- https://w1.fi/security/2019-1/
- FreeBSD-SA-19:03
- 20190515 FreeBSD Security Advisory FreeBSD-SA-19:03.wpa
- FEDORA-2019-f409af9fbe
- FEDORA-2019-eba1109acd
- FEDORA-2019-d03bae77f5
- http://packetstormsecurity.com/files/152914/FreeBSD-Security-Advisory-FreeBSD-SA-19-03.wpa.html
Modified: 2024-11-21
CVE-2019-9495
The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplicant with EAP-PWD support are vulnerable. The ability to install and execute applications is necessary for a successful attack. Memory access patterns are visible in a shared cache. Weak passwords may be cracked. Versions of hostapd/wpa_supplicant 2.7 and newer, are not vulnerable to the timing attack described in CVE-2019-9494. Both hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7 are affected.
- openSUSE-SU-2020:0222
- http://packetstormsecurity.com/files/152914/FreeBSD-Security-Advisory-FreeBSD-SA-19-03.wpa.html
- [debian-lts-announce] 20190731 [SECURITY] [DLA 1867-1] wpa security update
- FEDORA-2019-d03bae77f5
- FEDORA-2019-eba1109acd
- FEDORA-2019-f409af9fbe
- 20190515 FreeBSD Security Advisory FreeBSD-SA-19:03.wpa
- FreeBSD-SA-19:03
- https://w1.fi/security/2019-2/
- https://www.synology.com/security/advisory/Synology_SA_19_16
- openSUSE-SU-2020:0222
- https://www.synology.com/security/advisory/Synology_SA_19_16
- https://w1.fi/security/2019-2/
- FreeBSD-SA-19:03
- 20190515 FreeBSD Security Advisory FreeBSD-SA-19:03.wpa
- FEDORA-2019-f409af9fbe
- FEDORA-2019-eba1109acd
- FEDORA-2019-d03bae77f5
- [debian-lts-announce] 20190731 [SECURITY] [DLA 1867-1] wpa security update
- http://packetstormsecurity.com/files/152914/FreeBSD-Security-Advisory-FreeBSD-SA-19-03.wpa.html
Modified: 2024-11-21
CVE-2019-9496
An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps when processing the SAE confirm message when in hostapd/AP mode. All version of hostapd with SAE support are vulnerable. An attacker may force the hostapd process to terminate, performing a denial of service attack. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.7 are affected.
- openSUSE-SU-2020:0222
- http://packetstormsecurity.com/files/152914/FreeBSD-Security-Advisory-FreeBSD-SA-19-03.wpa.html
- FEDORA-2019-d03bae77f5
- FEDORA-2019-eba1109acd
- FEDORA-2019-f409af9fbe
- 20190515 FreeBSD Security Advisory FreeBSD-SA-19:03.wpa
- FreeBSD-SA-19:03
- https://w1.fi/security/2019-3/
- https://www.synology.com/security/advisory/Synology_SA_19_16
- openSUSE-SU-2020:0222
- https://www.synology.com/security/advisory/Synology_SA_19_16
- https://w1.fi/security/2019-3/
- FreeBSD-SA-19:03
- 20190515 FreeBSD Security Advisory FreeBSD-SA-19:03.wpa
- FEDORA-2019-f409af9fbe
- FEDORA-2019-eba1109acd
- FEDORA-2019-d03bae77f5
- http://packetstormsecurity.com/files/152914/FreeBSD-Security-Advisory-FreeBSD-SA-19-03.wpa.html
Modified: 2024-11-21
CVE-2019-9497
The implementations of EAP-PWD in hostapd EAP Server and wpa_supplicant EAP Peer do not validate the scalar and element values in EAP-pwd-Commit. This vulnerability may allow an attacker to complete EAP-PWD authentication without knowing the password. However, unless the crypto library does not implement additional checks for the EC point, the attacker will not be able to derive the session key or complete the key exchange. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.4 are affected. Both hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7 are affected.
- openSUSE-SU-2020:0222
- http://packetstormsecurity.com/files/152914/FreeBSD-Security-Advisory-FreeBSD-SA-19-03.wpa.html
- [debian-lts-announce] 20190731 [SECURITY] [DLA 1867-1] wpa security update
- FEDORA-2019-d03bae77f5
- FEDORA-2019-eba1109acd
- FEDORA-2019-f409af9fbe
- 20190515 FreeBSD Security Advisory FreeBSD-SA-19:03.wpa
- FreeBSD-SA-19:03
- https://w1.fi/security/2019-4/
- https://www.synology.com/security/advisory/Synology_SA_19_16
- openSUSE-SU-2020:0222
- https://www.synology.com/security/advisory/Synology_SA_19_16
- https://w1.fi/security/2019-4/
- FreeBSD-SA-19:03
- 20190515 FreeBSD Security Advisory FreeBSD-SA-19:03.wpa
- FEDORA-2019-f409af9fbe
- FEDORA-2019-eba1109acd
- FEDORA-2019-d03bae77f5
- [debian-lts-announce] 20190731 [SECURITY] [DLA 1867-1] wpa security update
- http://packetstormsecurity.com/files/152914/FreeBSD-Security-Advisory-FreeBSD-SA-19-03.wpa.html
Modified: 2024-11-21
CVE-2019-9498
The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may be able to use invalid scalar/element values to complete authentication, gaining session key and network access without needing or learning the password. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.4 are affected. Both hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7 are affected.
- openSUSE-SU-2020:0222
- [debian-lts-announce] 20190731 [SECURITY] [DLA 1867-1] wpa security update
- FEDORA-2019-d03bae77f5
- FEDORA-2019-eba1109acd
- FEDORA-2019-f409af9fbe
- 20190515 FreeBSD Security Advisory FreeBSD-SA-19:03.wpa
- FreeBSD-SA-19:03
- https://w1.fi/security/2019-4/
- https://www.synology.com/security/advisory/Synology_SA_19_16
- openSUSE-SU-2020:0222
- https://www.synology.com/security/advisory/Synology_SA_19_16
- https://w1.fi/security/2019-4/
- FreeBSD-SA-19:03
- 20190515 FreeBSD Security Advisory FreeBSD-SA-19:03.wpa
- FEDORA-2019-f409af9fbe
- FEDORA-2019-eba1109acd
- FEDORA-2019-d03bae77f5
- [debian-lts-announce] 20190731 [SECURITY] [DLA 1867-1] wpa security update
Modified: 2024-11-21
CVE-2019-9499
The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may complete authentication, session key and control of the data connection with a client. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.4 are affected. Both hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7 are affected.
- openSUSE-SU-2020:0222
- [debian-lts-announce] 20190731 [SECURITY] [DLA 1867-1] wpa security update
- FEDORA-2019-d03bae77f5
- FEDORA-2019-eba1109acd
- FEDORA-2019-f409af9fbe
- 20190515 FreeBSD Security Advisory FreeBSD-SA-19:03.wpa
- FreeBSD-SA-19:03
- https://w1.fi/security/2019-4/
- https://www.synology.com/security/advisory/Synology_SA_19_16
- openSUSE-SU-2020:0222
- https://www.synology.com/security/advisory/Synology_SA_19_16
- https://w1.fi/security/2019-4/
- FreeBSD-SA-19:03
- 20190515 FreeBSD Security Advisory FreeBSD-SA-19:03.wpa
- FEDORA-2019-f409af9fbe
- FEDORA-2019-eba1109acd
- FEDORA-2019-d03bae77f5
- [debian-lts-announce] 20190731 [SECURITY] [DLA 1867-1] wpa security update
Closed bugs
Closed vulnerabilities
BDU:2020-03226
Уязвимость функции Ipc::Mem::PageStack::pop прокси-сервера Squid, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2020-04037
Уязвимость компонента http/ContentLengthInterpreter.cc прокси-сервера Squid, позволяющая нарушителю отравлять содержимое кэша
BDU:2020-04147
Уязвимость прокси-сервера Squid, связанная с непоследовательной интерпретацией http-запросов, позволяющая нарушителю осуществлять межсайтовые сценарные атаки (XSS)
BDU:2020-04148
Уязвимость прокси-сервера Squid, связанная с непринятием мер по обработке последовательностей CRLF в HTTP-заголовках, позволяющая нарушителю внедрить произвольные HTTP-заголовки
BDU:2021-01722
Уязвимость функции peerDigestHandleReply() прокси-сервера Squid, связанная с недостатком механизма проверки вводимых данных, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-01723
Уязвимость механизма хранения nonce дайджест-аутентификации прокси-сервера Squid, связанная с целочисленным переполнением значения, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2021-01724
Уязвимость механизма обработки элементов ESI прокси-сервера Squid, связанная с выходом операции за допустимые границы буфера данных, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-01747
Уязвимость функции ESIExpression:: Evaluate прокси-сервера Squid, связанная с выходом операции за допустимые границы буфера данных, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2019-12519
An issue was discovered in Squid through 4.7. When handling the tag esi:when when ESI is enabled, Squid calls ESIExpression::Evaluate. This function uses a fixed stack buffer to hold the expression while it's being evaluated. When processing the expression, it could either evaluate the top of the stack, or add a new member to the stack. When adding a new member, there is no check to ensure that the stack won't overflow.
- openSUSE-SU-2020:0623
- openSUSE-SU-2020:0623
- [oss-security] 20200423 [ADVISORY] SQUID-2019:12 Multiple issues in ESI Response processing
- [oss-security] 20200423 [ADVISORY] SQUID-2019:12 Multiple issues in ESI Response processing
- https://gitlab.com/jeriko.one/security/-/blob/master/squid/CVEs/CVE-2019-12519.txt
- https://gitlab.com/jeriko.one/security/-/blob/master/squid/CVEs/CVE-2019-12519.txt
- [debian-lts-announce] 20200710 [SECURITY] [DLA 2278-1] squid3 security update
- [debian-lts-announce] 20200710 [SECURITY] [DLA 2278-1] squid3 security update
- GLSA-202005-05
- GLSA-202005-05
- https://security.netapp.com/advisory/ntap-20210205-0006/
- https://security.netapp.com/advisory/ntap-20210205-0006/
- USN-4356-1
- USN-4356-1
- DSA-4682
- DSA-4682
Modified: 2024-11-21
CVE-2019-12521
An issue was discovered in Squid through 4.7. When Squid is parsing ESI, it keeps the ESI elements in ESIContext. ESIContext contains a buffer for holding a stack of ESIElements. When a new ESIElement is parsed, it is added via addStackElement. addStackElement has a check for the number of elements in this buffer, but it's off by 1, leading to a Heap Overflow of 1 element. The overflow is within the same structure so it can't affect adjacent memory blocks, and thus just leads to a crash while processing.
- openSUSE-SU-2020:0623
- openSUSE-SU-2020:0623
- [oss-security] 20200423 [ADVISORY] SQUID-2019:12 Multiple issues in ESI Response processing
- [oss-security] 20200423 [ADVISORY] SQUID-2019:12 Multiple issues in ESI Response processing
- https://gitlab.com/jeriko.one/security/-/blob/master/squid/CVEs/CVE-2019-12521.txt
- https://gitlab.com/jeriko.one/security/-/blob/master/squid/CVEs/CVE-2019-12521.txt
- [debian-lts-announce] 20200710 [SECURITY] [DLA 2278-1] squid3 security update
- [debian-lts-announce] 20200710 [SECURITY] [DLA 2278-1] squid3 security update
- GLSA-202005-05
- GLSA-202005-05
- https://security.netapp.com/advisory/ntap-20210205-0006/
- https://security.netapp.com/advisory/ntap-20210205-0006/
- USN-4356-1
- USN-4356-1
- DSA-4682
- DSA-4682
Modified: 2024-11-21
CVE-2020-11945
An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. This occurs because the attacker can overflow the nonce reference counter (a short integer). Remote code execution may occur if the pooled token credentials are freed (instead of replayed as valid credentials).
- openSUSE-SU-2020:0623
- http://master.squid-cache.org/Versions/v4/changesets/squid-4-eeebf0f37a72a2de08348e85ae34b02c34e9a811.patch
- http://www.openwall.com/lists/oss-security/2020/04/23/2
- http://www.squid-cache.org/Versions/v4/changesets/squid-4-eeebf0f37a72a2de08348e85ae34b02c34e9a811.patch
- https://bugzilla.suse.com/show_bug.cgi?id=1170313
- https://github.com/squid-cache/squid/commit/eeebf0f37a72a2de08348e85ae34b02c34e9a811
- https://github.com/squid-cache/squid/pull/585
- [debian-lts-announce] 20200710 [SECURITY] [DLA 2278-1] squid3 security update
- FEDORA-2020-848065cc4c
- FEDORA-2020-56e809930e
- FEDORA-2020-a6a921a591
- GLSA-202005-05
- https://security.netapp.com/advisory/ntap-20210304-0004/
- USN-4356-1
- DSA-4682
- openSUSE-SU-2020:0623
- DSA-4682
- USN-4356-1
- https://security.netapp.com/advisory/ntap-20210304-0004/
- GLSA-202005-05
- FEDORA-2020-a6a921a591
- FEDORA-2020-56e809930e
- FEDORA-2020-848065cc4c
- [debian-lts-announce] 20200710 [SECURITY] [DLA 2278-1] squid3 security update
- https://github.com/squid-cache/squid/pull/585
- https://github.com/squid-cache/squid/commit/eeebf0f37a72a2de08348e85ae34b02c34e9a811
- https://bugzilla.suse.com/show_bug.cgi?id=1170313
- http://www.squid-cache.org/Versions/v4/changesets/squid-4-eeebf0f37a72a2de08348e85ae34b02c34e9a811.patch
- http://www.openwall.com/lists/oss-security/2020/04/23/2
- http://master.squid-cache.org/Versions/v4/changesets/squid-4-eeebf0f37a72a2de08348e85ae34b02c34e9a811.patch
Modified: 2024-11-21
CVE-2020-14058
An issue was discovered in Squid before 4.12 and 5.x before 5.0.3. Due to use of a potentially dangerous function, Squid and the default certificate validation helper are vulnerable to a Denial of Service when opening a TLS connection to an attacker-controlled server for HTTPS. This occurs because unrecognized error values are mapped to NULL, but later code expects that each error value is mapped to a valid error string.
- http://www.squid-cache.org/Advisories/SQUID-2020_6.txt
- http://www.squid-cache.org/Versions/v4/changesets/squid-4-93f5fda134a2a010b84ffedbe833d670e63ba4be.patch
- http://www.squid-cache.org/Versions/v5/changesets/squid-5-c6d1a4f6a2cbebceebc8a3fcd8f539ceb7b7f723.patch
- FEDORA-2020-cbebc5617e
- https://security.netapp.com/advisory/ntap-20210312-0001/
- http://www.squid-cache.org/Advisories/SQUID-2020_6.txt
- https://security.netapp.com/advisory/ntap-20210312-0001/
- FEDORA-2020-cbebc5617e
- http://www.squid-cache.org/Versions/v5/changesets/squid-5-c6d1a4f6a2cbebceebc8a3fcd8f539ceb7b7f723.patch
- http://www.squid-cache.org/Versions/v4/changesets/squid-4-93f5fda134a2a010b84ffedbe833d670e63ba4be.patch
Modified: 2024-11-21
CVE-2020-14059
An issue was discovered in Squid 5.x before 5.0.3. Due to an Incorrect Synchronization, a Denial of Service can occur when processing objects in an SMP cache because of an Ipc::Mem::PageStack::pop ABA problem during access to the memory page/slot management list.
- http://www.squid-cache.org/Advisories/SQUID-2020_5.txt
- http://www.squid-cache.org/Versions/v5/changesets/squid-5-7a5af8db8e0377c06ed9ffbdcb1334389c7cd8ab.patch
- https://security.netapp.com/advisory/ntap-20210312-0001/
- http://www.squid-cache.org/Advisories/SQUID-2020_5.txt
- https://security.netapp.com/advisory/ntap-20210312-0001/
- http://www.squid-cache.org/Versions/v5/changesets/squid-5-7a5af8db8e0377c06ed9ffbdcb1334389c7cd8ab.patch
Modified: 2024-11-21
CVE-2020-15049
An issue was discovered in http/ContentLengthInterpreter.cc in Squid before 4.12 and 5.x before 5.0.3. A Request Smuggling and Poisoning attack can succeed against the HTTP cache. The client sends an HTTP request with a Content-Length header containing "+\ "-" or an uncommon shell whitespace character prefix to the length field-value.
- openSUSE-SU-2020:1346
- openSUSE-SU-2020:1346
- openSUSE-SU-2020:1369
- openSUSE-SU-2020:1369
- http://www.squid-cache.org/Versions/v4/changesets/squid-4-ea12a34d338b962707d5078d6d1fc7c6eb119a22.patch
- http://www.squid-cache.org/Versions/v4/changesets/squid-4-ea12a34d338b962707d5078d6d1fc7c6eb119a22.patch
- http://www.squid-cache.org/Versions/v5/changesets/squid-5-485c9a7bb1bba88754e07ad0094647ea57a6eb8d.patch
- http://www.squid-cache.org/Versions/v5/changesets/squid-5-485c9a7bb1bba88754e07ad0094647ea57a6eb8d.patch
- https://github.com/squid-cache/squid/security/advisories/GHSA-qf3v-rc95-96j5
- https://github.com/squid-cache/squid/security/advisories/GHSA-qf3v-rc95-96j5
- [debian-lts-announce] 20201002 [SECURITY] [DLA 2394-1] squid3 security update
- [debian-lts-announce] 20201002 [SECURITY] [DLA 2394-1] squid3 security update
- FEDORA-2020-cbebc5617e
- FEDORA-2020-cbebc5617e
- https://security.netapp.com/advisory/ntap-20210312-0001/
- https://security.netapp.com/advisory/ntap-20210312-0001/
- USN-4551-1
- USN-4551-1
- DSA-4732
- DSA-4732
Modified: 2024-11-21
CVE-2020-15810
An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Smuggling attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows any client, including browser scripts, to bypass local security and poison the proxy cache and any downstream caches with content from an arbitrary source. When configured for relaxed header parsing (the default), Squid relays headers containing whitespace characters to upstream servers. When this occurs as a prefix to a Content-Length header, the frame length specified will be ignored by Squid (allowing for a conflicting length to be used from another Content-Length header) but relayed upstream.
- openSUSE-SU-2020:1346
- openSUSE-SU-2020:1346
- openSUSE-SU-2020:1369
- openSUSE-SU-2020:1369
- https://github.com/squid-cache/squid/security/advisories/GHSA-3365-q9qx-f98m
- https://github.com/squid-cache/squid/security/advisories/GHSA-3365-q9qx-f98m
- [debian-lts-announce] 20201002 [SECURITY] [DLA 2394-1] squid3 security update
- [debian-lts-announce] 20201002 [SECURITY] [DLA 2394-1] squid3 security update
- FEDORA-2020-6c58bff862
- FEDORA-2020-6c58bff862
- FEDORA-2020-63f3bd656e
- FEDORA-2020-63f3bd656e
- FEDORA-2020-73af8655eb
- FEDORA-2020-73af8655eb
- https://security.netapp.com/advisory/ntap-20210219-0007/
- https://security.netapp.com/advisory/ntap-20210219-0007/
- https://security.netapp.com/advisory/ntap-20210226-0006/
- https://security.netapp.com/advisory/ntap-20210226-0006/
- https://security.netapp.com/advisory/ntap-20210226-0007/
- https://security.netapp.com/advisory/ntap-20210226-0007/
- USN-4477-1
- USN-4477-1
- USN-4551-1
- USN-4551-1
- DSA-4751
- DSA-4751
Modified: 2024-11-21
CVE-2020-15811
An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Splitting attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows any client, including browser scripts, to bypass local security and poison the browser cache and any downstream caches with content from an arbitrary source. Squid uses a string search instead of parsing the Transfer-Encoding header to find chunked encoding. This allows an attacker to hide a second request inside Transfer-Encoding: it is interpreted by Squid as chunked and split out into a second request delivered upstream. Squid will then deliver two distinct responses to the client, corrupting any downstream caches.
- openSUSE-SU-2020:1346
- openSUSE-SU-2020:1346
- openSUSE-SU-2020:1369
- openSUSE-SU-2020:1369
- https://github.com/squid-cache/squid/security/advisories/GHSA-c7p8-xqhm-49wv
- https://github.com/squid-cache/squid/security/advisories/GHSA-c7p8-xqhm-49wv
- [debian-lts-announce] 20201002 [SECURITY] [DLA 2394-1] squid3 security update
- [debian-lts-announce] 20201002 [SECURITY] [DLA 2394-1] squid3 security update
- FEDORA-2020-6c58bff862
- FEDORA-2020-6c58bff862
- FEDORA-2020-63f3bd656e
- FEDORA-2020-63f3bd656e
- FEDORA-2020-73af8655eb
- FEDORA-2020-73af8655eb
- https://security.netapp.com/advisory/ntap-20210219-0007/
- https://security.netapp.com/advisory/ntap-20210219-0007/
- https://security.netapp.com/advisory/ntap-20210226-0006/
- https://security.netapp.com/advisory/ntap-20210226-0006/
- https://security.netapp.com/advisory/ntap-20210226-0007/
- https://security.netapp.com/advisory/ntap-20210226-0007/
- USN-4477-1
- USN-4477-1
- USN-4551-1
- USN-4551-1
- DSA-4751
- DSA-4751
Modified: 2024-11-21
CVE-2020-24606
Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handling of a crafted Cache Digest response message. This only occurs when cache_peer is used with the cache digests feature. The problem exists because peerDigestHandleReply() livelocking in peer_digest.cc mishandles EOF.
- openSUSE-SU-2020:1346
- openSUSE-SU-2020:1346
- openSUSE-SU-2020:1369
- openSUSE-SU-2020:1369
- http://www.squid-cache.org/Versions/v4/changesets/SQUID-2020_9.patch
- http://www.squid-cache.org/Versions/v4/changesets/SQUID-2020_9.patch
- https://github.com/squid-cache/squid/security/advisories/GHSA-vvj7-xjgq-g2jg
- https://github.com/squid-cache/squid/security/advisories/GHSA-vvj7-xjgq-g2jg
- [debian-lts-announce] 20201002 [SECURITY] [DLA 2394-1] squid3 security update
- [debian-lts-announce] 20201002 [SECURITY] [DLA 2394-1] squid3 security update
- FEDORA-2020-6c58bff862
- FEDORA-2020-6c58bff862
- FEDORA-2020-63f3bd656e
- FEDORA-2020-63f3bd656e
- FEDORA-2020-73af8655eb
- FEDORA-2020-73af8655eb
- https://security.netapp.com/advisory/ntap-20210219-0007/
- https://security.netapp.com/advisory/ntap-20210219-0007/
- https://security.netapp.com/advisory/ntap-20210226-0006/
- https://security.netapp.com/advisory/ntap-20210226-0006/
- https://security.netapp.com/advisory/ntap-20210226-0007/
- https://security.netapp.com/advisory/ntap-20210226-0007/
- USN-4477-1
- USN-4477-1
- USN-4551-1
- USN-4551-1
- DSA-4751
- DSA-4751
Closed bugs
Не работает виртуальная клавиатура в OpenBoard
Не работает виртуальная клавиатура в OpenBoard