SB2020070244 - Fedora 31 update for squid
Published: July 2, 2020 Updated: April 25, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Inconsistent interpretation of HTTP requests (CVE-ID: CVE-2020-15049)
The vulnerability allows a remote attacker to perform cache poisoning attack.
The vulnerability exists in the way Squid processes client's requests. A remote client can send specially crafted data in the request to perform request smuggling and poison the HTTP cache contents with crafted HTTP(S) request messages.
Successful exploitation of the vulnerability requires an upstream server to participate in the smuggling and generate the poison response sequence.
2) Exposed dangerous method or function (CVE-ID: CVE-2020-14058)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to usage of potentially dangerous function when processing TLS certificates. A remote client can perform a denial of service attack when opening TLS connections.
Remediation
Install update from vendor's website.