VYPR

rpm package

suse/squid&distro=SUSE Linux Enterprise Server for SAP Applications 11 SP4

pkg:rpm/suse/squid&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4

Vulnerabilities (4)

  • CVE-2016-4554HigMay 10, 2016
    affected < 2.7.STABLE5-2.12.29.1fixed 2.7.STABLE5-2.12.29.1

    mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin restrictions and possibly conduct cache-poisoning attacks via a crafted HTTP Host header, aka a "header smuggling" issue.

  • CVE-2016-4051HigApr 25, 2016
    affected < 2.7.STABLE5-2.12.29.1fixed 2.7.STABLE5-2.12.29.1

    Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow remote attackers to cause a denial of service or execute arbitrary code by seeding manager reports with crafted data.

  • CVE-2014-9749Nov 6, 2015
    affected < 2.7.STABLE5-2.12.24.2fixed 2.7.STABLE5-2.12.24.2

    Squid 3.4.4 through 3.4.11 and 3.5.0.1 through 3.5.1, when Digest authentication is used, allow remote authenticated users to retain access by leveraging a stale nonce, aka "Nonce replay vulnerability."

  • CVE-2014-6270Sep 12, 2014
    affected < 2.7.STABLE5-2.12.24.2fixed 2.7.STABLE5-2.12.24.2

    Off-by-one error in the snmpHandleUdp function in snmp_core.cc in Squid 2.x and 3.x, when an SNMP port is configured, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted UDP SNMP request, which triggers a heap-based buffer