CentOS 6 ELS: squid package gradual rollout completed

TuxCare Team

September 6, 2021

changelog

A new updated squid package with the fix for the CVE-2020-14058 and CVE-2020-15049 within CentOS 6 ELS has been rolled out to 100% and is now available for download from our production repository.

CHANGELOG

squid-3.1.23-30.el6.cloudlinux.els

  • Fix handling of unknown SSL errors which resulted in denial of service (CVE-2020-14058)
  • Fix incorrect validation of Content-Length field leading to http smuggling and Poisoning attack (CVE-2020-15049)

UPDATE COMMAND

yum update squid*

 

Stay in the Loop