[CLSA-2025:1761575970] Fix of 6 CVEs
Type:
security
Severity:
Important
Release date:
2025-10-27 14:39:39 UTC
Description:
* SECURITY UPDATE: potential Denial of Service via TLS connection - debian/patches/CVE-2020-14058.patch: Fix sending of unknown validation errors to cert validator - CVE-2020-14058 * SECURITY UPDATE: improper Validation of Specified Index leads to Denial of Service via TLS Handshake vulnerability - debian/patches/CVE-2023-46724.patch: Fix validation of certificates with CN=* due to Buffer UnderRead in SSL CN Parsing issue (#1523) - CVE-2023-46724 * SECURITY UPDATE: denial of Service vulnerability in HTTP Chunked decoder due to uncontrolled recursion bug - debian/patches/CVE-2024-25111.patch: Fix infinite recursion when parsing HTTP chunks, prevent progress in call chain by stopping HttpStateData recursion - CVE-2024-25111 * SECURITY UPDATE: denial of Service vulnerability in the NTLM authentication credentials parser due to incorrect input validation - debian/patches/CVE-2020-8517.patch: Fix incorrect input validation allowing writing outside of buffer and leading to denial of service - CVE-2020-8517 * SECURITY UPDATE: denial of Service vulnerability against HTTP header parsing due to a Collapse of Data into Unsafe Value - debian/patches/CVE-2024-25617.patch: Improve handling of expanding HTTP header values to prevent DoS - CVE-2024-25617 * SECURITY UPDATE: denial of Service vulnerability by a trusted server - debian/rules: Disable ESI due to unfixed multiple issues in ESI causing DoS by a trusted server - debian/control: Remove dependencies used by ESI - CVE-2024-45802
Updated packages:
  • squid_4.6-1+deb10u10+tuxcare.els1_amd64.deb
    sha:f6ab2fab6e59af569e63d5523611884b7bbe8138
  • squid-cgi_4.6-1+deb10u10+tuxcare.els1_amd64.deb
    sha:4c594136f4f4c32a86dbf8dd5fa1b433df895857
  • squid-common_4.6-1+deb10u10+tuxcare.els1_all.deb
    sha:cb9e61c1b50a63a0bbcce6e89f05e59d7e3b6b47
  • squid-purge_4.6-1+deb10u10+tuxcare.els1_amd64.deb
    sha:66170871d1df3093aa97b4a3ad3375197f64f773
  • squid3_4.6-1+deb10u10+tuxcare.els1_all.deb
    sha:f18f61dc50e834ae0e2194a0b67626153e48fc83
  • squidclient_4.6-1+deb10u10+tuxcare.els1_amd64.deb
    sha:27a1964f3383cd999d943c851e49774ca4829fcd
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.