openSUSE Security Update : squid (openSUSE-2017-127)
Medium Nessus Plugin ID 96648
SynopsisThe remote openSUSE host is missing a security update.
DescriptionThis update for squid fixes the following issues :
- CVE-2016-10002: Fixed incorrect processing of responses to If-None-Modified HTTP conditional requests. This allowed responses containing private data to clients it should not have reached (bsc#1016168)
- CVE-2014-9749: Prevent nonce replay in Digest authentication, preventing the reuse of stale auth tokens (bsc#949942)
This update was imported from the SUSE:SLE-12:Update update project.
SolutionUpdate the affected squid packages.