package/squid: security bump to version 4.11
authorFabrice Fontaine <fontaine.fabrice@gmail.com>
Wed, 6 May 2020 20:15:41 +0000 (22:15 +0200)
committerThomas Petazzoni <thomas.petazzoni@bootlin.com>
Thu, 7 May 2020 21:13:43 +0000 (23:13 +0200)
commitb365c642369ca76cb138fd0b5be6457865a3d5ce
treebbb58a581cd8343d364097e7f014dc02469bd54b
parent047832a1f2f4a00a314b16289e73757f7978b2f5
package/squid: security bump to version 4.11

Fix CVE-2020-11945: An issue was discovered in Squid before 5.0.2. A
remote attacker can replay a sniffed Digest Authentication nonce to gain
access to resources that are otherwise forbidden. This occurs because
the attacker can overflow the nonce reference counter (a short integer).
Remote code execution may occur if the pooled token credentials are
freed (instead of replayed as valid credentials).

http://www.squid-cache.org/Advisories/SQUID-2020_4.txt

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
package/squid/squid.hash
package/squid/squid.mk