On 2020/04/23 04:54, Stuart Henderson wrote:
> CVSROOT:      /cvs
> Module name:  ports
> Changes by:   [email protected]   2020/04/23 04:54:48
> 
> Modified files:
>       www/squid      : Makefile distinfo 
> 
> Log message:
> update to squid-4.11
> 
> SQUID-2020:3 - Due to incorrect buffer handling Squid is vulnerable to
> cache poisoning, remote execution, and denial of service attacks when
> processing ESI responses.

oops, this one was actually SQUID-2019:12

> SQUID-2020:4 - Due to an integer overflow bug Squid is vulnerable to
> credential replay and remote code execution attacks against HTTP Digest
> Authentication tokens.
> 

Reply via email to