SecurityTracker.com
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 


Category:   Application (Web Server/CGI)  >   Squid Vendors:   Squid-cache.org
(Oracle Issues Fix for Oracle Linux) Squid Conditional Request Handling Flaw Lets Remote Users Obtain Potentially Sensitive Information on the Target System
SecurityTracker Alert ID:  1037692
SecurityTracker URL:  http://securitytracker.com/id/1037692
CVE Reference:   CVE-2016-10002   (Links to External Site)
Date:  Jan 25 2017
Impact:   Disclosure of authentication information, Disclosure of system information, Disclosure of user information
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): 3.1 - 3.5.22, 4.0 - 4.0.16
Description:   A vulnerability was reported in Squid. A remote user can obtain potentially sensitive information on the target system.

A remote user can send a specially crafted request to trigger a flaw in the processing of conditional requests and cause the target system to return responses containing potentially sensitive information about another client's browsing session. This information may include authentication credentials.

Saulius Lapinskas from Lithuanian State Social Insurance Fund Board reported this vulnerability.

Impact:   A remote user can obtain potentially sensitive information about other user sessions on the target system.
Solution:   Oracle has issued a fix.

The Oracle Linux advisory is available at:

http://linux.oracle.com/errata/ELSA-2017-0182.html

Vendor URL:  linux.oracle.com/errata/ELSA-2017-0182.html (Links to External Site)
Cause:   Access control error
Underlying OS:  Linux (Oracle)
Underlying OS Comments:  7

Message History:   This archive entry is a follow-up to the message listed below.
Dec 21 2016 Squid Conditional Request Handling Flaw Lets Remote Users Obtain Potentially Sensitive Information on the Target System



 Source Message Contents

Subject:  [El-errata] ELSA-2017-0182 Moderate: Oracle Linux 7 squid security update

Oracle Linux Security Advisory ELSA-2017-0182

http://linux.oracle.com/errata/ELSA-2017-0182.html

The following updated rpms for Oracle Linux 7 have been uploaded to the 
Unbreakable Linux Network:

x86_64:
squid-3.5.20-2.el7_3.2.x86_64.rpm
squid-migration-script-3.5.20-2.el7_3.2.x86_64.rpm
squid-sysvinit-3.5.20-2.el7_3.2.x86_64.rpm


SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates/squid-3.5.20-2.el7_3.2.src.rpm



Description of changes:

[7:3.5.20-2.2]
- Resolves: #1412735 - CVE-2016-10002 squid: Information disclosure in HTTP
   request processing


_______________________________________________
El-errata mailing list
El-errata@oss.oracle.com
https://oss.oracle.com/mailman/listinfo/el-errata
 
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

This web site uses cookies for web analytics. Learn More

Copyright 2019, SecurityGlobal.net LLC