Go to file
Catalin Enache d46c89ae44 squid: CVE-2016-4553
client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10
does not properly ignore the Host header when absolute-URI
is provided, which allows remote attackers to conduct
cache-poisoning attacks via an HTTP request.

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-4553

Backported upstream patch:
http://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-14039.patch

Signed-off-by: Catalin Enache <catalin.enache@windriver.com>
Signed-off-by: Martin Jansa <Martin.Jansa@gmail.com>
Signed-off-by: Joe MacDonald <joe_macdonald@mentor.com>
2016-06-01 19:35:50 -04:00
contrib contrib: print oldline within single quotes 2016-01-04 14:56:24 +01:00
meta-efl meta-efl: use bb.utils.contains() instead of base_contains() 2016-04-28 10:38:39 +02:00
meta-filesystems Add simple-mtpfs recipe 2016-04-21 21:34:09 +02:00
meta-gnome florence: move to latest GTK2 version 0.5.4 2016-05-27 15:39:14 +02:00
meta-gpe fbreader: add cflags fix for fribidi 0.19.7 2016-05-06 12:40:26 +02:00
meta-initramfs initramfs-kexecboot-klibc-image: Skip for nios2 2016-05-27 15:39:10 +02:00
meta-multimedia fluidsynth: set correct portaudio packageconfig dependency 2016-05-06 12:40:25 +02:00
meta-networking squid: CVE-2016-4553 2016-06-01 19:35:50 -04:00
meta-oe openct: Fix rootfs creation errors 2016-05-27 15:39:14 +02:00
meta-perl libhtml-parser-perl: update to 3.72 2016-04-21 21:33:18 +02:00
meta-python python-thrift: update to version 0.9.3 2016-05-27 15:39:13 +02:00
meta-ruby libgxim: move from meta-ruby back to meta-oe 2015-12-18 12:39:50 +01:00
meta-systemd avahi: rename the bbappend to apply for all versions 2016-02-20 14:51:57 +01:00
meta-webserver sthttpd: update to 2.27.0 2016-05-27 15:39:10 +02:00
meta-xfce xfce4-eyes-plugin: update to 4.4.5 2016-05-06 12:40:25 +02:00
.gitignore gitignore: Ignore Edit backup files, patches, .rej, .orig, .swp 2013-11-24 15:19:27 +01:00
COPYING.MIT add README and license for this layer 2011-02-13 16:47:32 +01:00
README README: add top level readme, update meta-oe one 2011-10-17 09:27:01 +02:00

Collection of layers for the OE-core universe

Please see the respective READMEs in the layer subdirectories