buildroot/package/squid/squid.hash
Fabrice Fontaine b365c64236 package/squid: security bump to version 4.11
Fix CVE-2020-11945: An issue was discovered in Squid before 5.0.2. A
remote attacker can replay a sniffed Digest Authentication nonce to gain
access to resources that are otherwise forbidden. This occurs because
the attacker can overflow the nonce reference counter (a short integer).
Remote code execution may occur if the pooled token credentials are
freed (instead of replayed as valid credentials).

http://www.squid-cache.org/Advisories/SQUID-2020_4.txt

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2020-05-07 23:13:43 +02:00

7 lines
386 B
Plaintext

# From http://www.squid-cache.org/Versions/v4/squid-4.11.tar.xz.asc
md5 10f34e852153a9996aa4614670e2bda1 squid-4.11.tar.xz
sha1 053277bf5497163ffc9261b9807abda5959bb6fc squid-4.11.tar.xz
# Locally calculated
sha256 4ed947612410263f57ad0e39bfd087e60fb714f028d7d3b0e469943efd34287d squid-4.11.tar.xz
sha256 8177f97513213526df2cf6184d8ff986c675afb514d4e68a404010521b880643 COPYING