Bugzilla – Bug 1217654
VUL-0: CVE-2023-50269: squid, squid3: X-Forwarded-For Stack Overflow
Last modified: 2024-03-07 10:07:53 UTC
X-Forwarded-For Stack Overflow Report: https://megamansec.github.io/Squid-Security-Audit/xff-stackoverflow.html Upstream fix: https://github.com/squid-cache/squid/commit/45b6522eb80a6d12f75630fe1c132b52fc3f1624
SUSE-SU-2023:4698-1: An update that solves two vulnerabilities and has one security fix can now be installed. Category: security (important) Bug References: 1217654, 1217813, 1217815 CVE References: CVE-2023-49285, CVE-2023-49286 Sources used: openSUSE Leap 15.5 (src): squid-5.7-150400.3.20.1 Server Applications Module 15-SP4 (src): squid-5.7-150400.3.20.1 Server Applications Module 15-SP5 (src): squid-5.7-150400.3.20.1 openSUSE Leap 15.4 (src): squid-5.7-150400.3.20.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2023:4724-1: An update that solves two vulnerabilities and has one security fix can now be installed. Category: security (important) Bug References: 1217654, 1217813, 1217815 CVE References: CVE-2023-49285, CVE-2023-49286 Sources used: SUSE Linux Enterprise High Performance Computing 12 SP5 (src): squid-4.17-4.38.1 SUSE Linux Enterprise Server 12 SP5 (src): squid-4.17-4.38.1 SUSE Linux Enterprise Server for SAP Applications 12 SP5 (src): squid-4.17-4.38.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2023:4825-1: An update that solves two vulnerabilities and has one security fix can now be installed. Category: security (important) Bug References: 1217654, 1217813, 1217815 CVE References: CVE-2023-49285, CVE-2023-49286 Sources used: SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 (src): squid-4.17-150000.5.46.1 SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (src): squid-4.17-150000.5.46.1 SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 (src): squid-4.17-150000.5.46.1 SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (src): squid-4.17-150000.5.46.1 SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 (src): squid-4.17-150000.5.46.1 SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (src): squid-4.17-150000.5.46.1 SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (src): squid-4.17-150000.5.46.1 SUSE Linux Enterprise Server for SAP Applications 15 SP1 (src): squid-4.17-150000.5.46.1 SUSE Linux Enterprise Server for SAP Applications 15 SP2 (src): squid-4.17-150000.5.46.1 SUSE Linux Enterprise Server for SAP Applications 15 SP3 (src): squid-4.17-150000.5.46.1 SUSE Enterprise Storage 7.1 (src): squid-4.17-150000.5.46.1 SUSE CaaS Platform 4.0 (src): squid-4.17-150000.5.46.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2024:0296-1: An update that solves two vulnerabilities can now be installed. Category: security (important) Bug References: 1217654, 1219131 CVE References: CVE-2023-50269, CVE-2024-23638 Sources used: SUSE Linux Enterprise High Performance Computing 12 SP5 (src): squid-4.17-4.41.1 SUSE Linux Enterprise Server 12 SP5 (src): squid-4.17-4.41.1 SUSE Linux Enterprise Server for SAP Applications 12 SP5 (src): squid-4.17-4.41.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2024:0298-1: An update that solves two vulnerabilities can now be installed. Category: security (important) Bug References: 1217654, 1219131 CVE References: CVE-2023-50269, CVE-2024-23638 Sources used: SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (src): squid-4.17-150000.5.49.1 SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (src): squid-4.17-150000.5.49.1 SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (src): squid-4.17-150000.5.49.1 SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (src): squid-4.17-150000.5.49.1 SUSE Linux Enterprise Server for SAP Applications 15 SP2 (src): squid-4.17-150000.5.49.1 SUSE Linux Enterprise Server for SAP Applications 15 SP3 (src): squid-4.17-150000.5.49.1 SUSE Enterprise Storage 7.1 (src): squid-4.17-150000.5.49.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2024:0455-1: An update that solves two vulnerabilities can now be installed. Category: security (important) Bug References: 1217654, 1219131 CVE References: CVE-2023-50269, CVE-2024-23638 Sources used: openSUSE Leap 15.4 (src): squid-5.7-150400.3.23.1 openSUSE Leap 15.5 (src): squid-5.7-150400.3.23.1 Server Applications Module 15-SP5 (src): squid-5.7-150400.3.23.1 SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (src): squid-5.7-150400.3.23.1 SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (src): squid-5.7-150400.3.23.1 SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (src): squid-5.7-150400.3.23.1 SUSE Linux Enterprise Server for SAP Applications 15 SP4 (src): squid-5.7-150400.3.23.1 SUSE Manager Proxy 4.3 (src): squid-5.7-150400.3.23.1 SUSE Manager Retail Branch Server 4.3 (src): squid-5.7-150400.3.23.1 SUSE Manager Server 4.3 (src): squid-5.7-150400.3.23.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.