From cf1ad20812e166c27ff8e9100c489ef0f71e0e17d8004ed17746ab1209f71bcf Mon Sep 17 00:00:00 2001 From: Adam Majer Date: Mon, 29 Jun 2020 07:59:39 +0000 Subject: [PATCH] * HTTP: validate Content-Length value prefix (CVE-CVE-2020-15049, bsc#1173455) OBS-URL: https://build.opensuse.org/package/show/server:proxy/squid?expand=0&rev=216 --- squid.changes | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/squid.changes b/squid.changes index 3fd21f0..1144159 100644 --- a/squid.changes +++ b/squid.changes @@ -6,7 +6,7 @@ Sun Jun 21 05:28:33 UTC 2020 - Andreas Stieger during HTTPS or SSL-Bump connections (CVE-2020-14059, bsc#1173304) * Regression Fix: Revert to slow search for new SMP shm pages * Fix Negative responses are never cached - * HTTP: validate Content-Length value prefix + * HTTP: validate Content-Length value prefix (CVE-CVE-2020-15049, bsc#1173455) * HTTP: add flexible RFC 3986 URI encoder * Fix stall if transaction overwrites a recently active cache entry