All errata/sisyphus_e2k/ALT-PU-2022-6237-1
ALT-PU-2022-6237-1

Package update squid in branch sisyphus_e2k

Version5.7-alt1
Task#0
Published2022-09-21
Max severityHIGH
Severity:

Closed issues (6)

BDU:2022-04051
MEDIUM6.5

Уязвимость реализации сетевого протокола Gopher прокси-сервера Squid, позволяющая нарушителю вызвать отказ в обслуживании

Published: 2022-07-04Modified: 2026-01-20
CVSS 3.xMEDIUM 6.5
CVSS:3.x/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.0HIGH 7.8
CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:N/A:C
References
BDU:2023-00066
MEDIUM6.5

Уязвимость кэширующего прокси-сервера Squid, связанная с неправильным контролем доступа, позволяющая нарушителю получить доступ к конфиденциальной информации

Published: 2023-01-12Modified: 2026-01-20
CVSS 3.xMEDIUM 6.5
CVSS:3.x/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.0MEDIUM 6.8
CVSS:2.0/AV:N/AC:L/Au:S/C:C/I:N/A:N
References
BDU:2023-01309
HIGH8.9

Уязвимость интерфейса Security Support Provider Interface (SSPI) и реализации сетевого протокола Server Message Block (SMB) прокси-сервера Squid, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании

Published: 2023-03-20Modified: 2026-01-20
CVSS 3.xHIGH 8.9
CVSS:3.x/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:H
CVSS 2.0HIGH 7.3
CVSS:2.0/AV:N/AC:H/Au:N/C:C/I:P/A:C
References
CVE-2022-41317
MEDIUM6.5

An issue was discovered in Squid 4.9 through 4.17 and 5.0.6 through 5.6. Due to inconsistent handling of internal URIs, there can be Exposure of Sensitive Information about clients using the proxy via an HTTPS request to an internal cache manager URL. This is fixed in 5.7.

Published: 2022-12-25Modified: 2025-04-14
CVSS 3.xMEDIUM 6.5
CVSS:3.x/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVE-2022-41318
HIGH8.6

A buffer over-read was discovered in libntlmauth in Squid 2.5 through 5.6. Due to incorrect integer-overflow protection, the SSPI and SMB authentication helpers are vulnerable to reading unintended memory locations. In some configurations, cleartext credentials from these locations are sent to a client. This is fixed in 5.7.

Published: 2022-12-25Modified: 2025-04-14
CVSS 3.xHIGH 8.6
CVSS:3.x/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N