СloudLinux Blog

CloudLinux OS 6 ELS: squid package has been scheduled for gradual rollout

Written by Inessa Atmachian | Aug 25, 2021 3:30:17 PM

A new updated squid package within CloudLinux OS 6 ELS has been scheduled for gradual rollout from our production repository.

Rollout slot: 4
Rolled out to: 1%
ETA for 100% rollout: September 3

Changelog

squid-3.1.23-30.el6.cloudlinux.els

  • Fix handling of unknown SSL errors which resulted in denial of service (CVE-2020-14058)
  • Fix incorrect validation of Content-Length field leading to Http smuggling and Poisoning attack (CVE-2020-15049)

Update command

yum update squid*

Immediate update (via bypass)

yum update squid* --enablerepo=cloudlinux-rollout-4-bypass