QID 356435
Date Published: 2023-10-31
QID 356435: Amazon Linux Security Advisory for squid : ALAS2-2023-2310
Squid before 4.4 has xss via a crafted x.509 certificate during http(s) error page generation for certificate errors. (
( CVE-2018-19131) a memory leak was discovered in the way squid handles snmp denied queries.
A remote attacker may use this flaw to exhaust the resources on the server machine. (
( CVE-2018-19132)
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.
Solution
Please refer to Amazon advisory: ALAS2-2023-2310 for affected packages and patching details, or update with your package manager.
Vendor References
- ALAS2-2023-2310 -
alas.aws.amazon.com/AL2/ALAS-2023-2310.html
CVEs related to QID 356435
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ALAS2-2023-2310 | amazon linux 2 |
|