Release date:
2026-07-22 10:35:24 UTC
Description:
* SECURITY UPDATE: out-of-bounds read in FTP gateway directory-listing
parser
- debian/patches/CVE-2026-47729.patch: guard the whitespace-skipping
strchr(w_space, *copyFrom) checks in ftpListParseParts() with a
'*copyFrom &&' short-circuit so a listing date that is not followed
by a filename cannot advance parsing past the input buffer
- CVE-2026-47729
* SECURITY UPDATE: heap buffer overflow in cache digest reply handling
- debian/patches/CVE-2026-50012.patch: bounds-check the received mask
data size against the declared mask_size before the memcpy in
peerDigestSwapInMask(), aborting the digest fetch when the
on-the-wire size is larger than the mask
- CVE-2026-50012
Updated packages:
-
squid_4.10-1ubuntu1.13+tuxcare.els5_amd64.deb
sha:ff28f6d44bcb617c79cf67ec9a95a52e46266bd9
-
squid-cgi_4.10-1ubuntu1.13+tuxcare.els5_amd64.deb
sha:6aab75f102c9a442b8a8d4caff727381bdc7885a
-
squid-common_4.10-1ubuntu1.13+tuxcare.els5_all.deb
sha:ed08628e8ebfe763c79776f99266bd9fd5fe68b6
-
squid-purge_4.10-1ubuntu1.13+tuxcare.els5_amd64.deb
sha:18435c86447030de37746971b8b2b59b44e84cc1
-
squidclient_4.10-1ubuntu1.13+tuxcare.els5_amd64.deb
sha:66aa597aa66d60949c4c985f83fa1facd9abdb1c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.