SB2020063010 - OpenSUSE Linux update for squid
Published: June 30, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource management error (CVE-ID: CVE-2020-14059)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to incorrect synchronization when processing objects in an SMP cache. A remote client trigger a Squid worker assertion and perform a denial of service (DoS) attack.
This attack is limited to SMP Squids using shared memory cache and/or an SMP rock disk cache.
Remediation
Install update from vendor's website.