Security update for squid

This update for squid fixes the following issues:

- CVE-2016-10003: Prevent incorrect forwarding of cached private responses when Collapsed Forwarding feature is enabled. This allowed remote attacker (proxy user) to discover private and sensitive information about another user (bsc#1016169).
- CVE-2016-10002: Fixed incorrect processing of responses to If-None-Modified HTTP conditional requests. This allowed responses containing private data to clients it should not have reached (bsc#1016168).
- CVE-2014-9749: Prevent nonce replay in Digest authentication, preventing the reuse of stale auth tokens (bsc#949942).

This update was imported from the SUSE:SLE-12-SP2:Update update project.

Fixed bugs
bnc#1016168
VUL-0: CVE-2016-10002: squid: Incorrect processing of responses to If-None-Modified HTTP conditional requests
bnc#1016169
VUL-0: CVE-2016-10003: squid: Incorrect HTTP Request header comparison results in Collapsed Forwarding feature
bnc#949942
VUL-0: CVE-2014-9749: squid,squid3: Nonce replay vulnerability in Digest authentication
Selected Binaries
openSUSE Build Service is sponsored by