meta-openembedded/meta-networking/recipes-daemons
Peter Marko 508a2e6b94
squid: handle CVE-2024-45802
According to [1] the ESI implementation in squid feature is vulnerable
without any fix available.

NVD says it's fixed in 6.10, however the change in this release only
disables ESI by default (which we always did via PACKAGECONFIG).
This means CVE report would say Patched even if the vulnerability is
still present if someone adapts squid PACKAGECONFIG.

Commit in master branch related to this CVE is [2].
Title is "Remove Edge Side Include (ESI) protocol" and it's also what it
does. So there will never be a fix for these ESI vulnerabilities.
Based on this, remove vulnerable ESI PACKAGECONFIG already now.

[1] https://github.com/squid-cache/squid/security/advisories/GHSA-f975-v7qw-q7hj
[2] 5eb89ef3d8

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2024-11-19 13:50:56 -08:00
..
atftp recipes: Start WORKDIR -> UNPACKDIR transition 2024-05-23 08:44:44 -07:00
autofs autofs: upgrade 5.1.8 -> 5.1.9 2024-09-10 20:13:08 -07:00
igmpproxy recipes: Update LICENSE variable to use SPDX license identifiers 2022-03-04 17:41:45 -08:00
ippool ippool: Fix buildpaths QA error 2024-08-19 10:19:31 -07:00
iscsi-initiator-utils iscsi-initiator-utils: upgrade 2.1.8 -> 2.1.10 2024-06-07 09:11:57 -07:00
keepalived keepalived: Make build reproducible 2024-08-15 23:20:05 -07:00
lldpd recipes: Start WORKDIR -> UNPACKDIR transition 2024-05-23 08:44:44 -07:00
ncftp recipes: ignore various issues fatal with gcc-14 2024-07-08 08:42:43 -07:00
networkd-dispatcher networkd-dispatcher: Add dependency on python3-json 2024-04-30 08:20:34 -07:00
openhpi recipes: Start WORKDIR -> UNPACKDIR transition 2024-05-23 08:44:44 -07:00
opensaf *.patch: add Upstream-Status to all patches 2023-06-21 09:15:20 -07:00
postfix recipes: Start WORKDIR -> UNPACKDIR transition 2024-05-23 08:44:44 -07:00
proftpd proftpd: Upgrade to 1.3.8b 2024-08-15 23:20:05 -07:00
ptpd recipes: Start WORKDIR -> UNPACKDIR transition 2024-05-23 08:44:44 -07:00
pure-ftpd pure-ftpd: upgrade 1.0.51 -> 1.0.52 2024-09-30 07:34:23 -07:00
radvd recipes: Start WORKDIR -> UNPACKDIR transition 2024-05-23 08:44:44 -07:00
squid squid: handle CVE-2024-45802 2024-11-19 13:50:56 -08:00
tftp-hpa recipes: Start WORKDIR -> UNPACKDIR transition 2024-05-23 08:44:44 -07:00
vblade recipes: Start WORKDIR -> UNPACKDIR transition 2024-05-23 08:44:44 -07:00
vsftpd recipes: Start WORKDIR -> UNPACKDIR transition 2024-05-23 08:44:44 -07:00