Hide Forgot
Due to Improper Input Validation Squid is vulnerable to a Denial of Service attack against the machine operating Squid. Upstream Advisory: https://github.com/squid-cache/squid/security/advisories/GHSA-vvj7-xjgq-g2jg Affected Versions: 3.0-4.12, 5.0.1-5.0.3 Fixed Versions: 4.13, 5.0.4
Created squid tracking bugs for this issue: Affects: fedora-all [bug 1871706]
Mitigation: Add the no-digest option to all cache_peer lines in squid.conf
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2020:4082 https://access.redhat.com/errata/RHSA-2020:4082
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-24606
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2020:4743 https://access.redhat.com/errata/RHSA-2020:4743
External References: https://github.com/squid-cache/squid/security/advisories/GHSA-vvj7-xjgq-g2jg