USN-4059-1: Squid vulnerabilities

15 July 2019

Several security issues were fixed in Squid.

Releases

Packages

  • squid - Web proxy cache server
  • squid3 - Web proxy cache server

Details

It was discovered that Squid incorrectly handled certain SNMP packets. A
remote attacker could possibly use this issue to cause memory consumption,
leading to a denial of service. This issue only affected Ubuntu 16.04 LTS
and Ubuntu 18.04 LTS. (CVE-2018-19132)

It was discovered that Squid incorrectly handled the cachemgr.cgi web
module. A remote attacker could possibly use this issue to conduct
cross-site scripting (XSS) attacks. (CVE-2019-13345)

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 19.04
Ubuntu 18.04
Ubuntu 16.04

In general, a standard system update will make all the necessary changes.

Related notices