Squid is a high-performance proxy caching server. It handles all requests in a single, non-blocking, I/O-driven process and keeps meta data and implements negative caching of failed requests.
Security Fix(es):
Description: Due to chunked decoder lenience Squid is vulnerable to Request/Response smuggling attacks when parsing HTTP/1.1 and ICAP messages
Reference: https://github.com/squid-cache/squid/security/advisories/GHSA-j83v-w3p4-5cqh
Affected versions: 2.6-6.3. Patched in 6.4.(CVE-2023-46846)
Description: Due to a buffer overflow bug Squid is vulnerable to a Denial of Service attack against HTTP Digest Authentication
Reference: https://github.com/squid-cache/squid/security/advisories/GHSA-phqj-m8gv-cq4g
Affected versions: 3.2.0.1-5.9, 6.0-6.3(CVE-2023-46847)
{ "severity": "Critical" }
{ "aarch64": [ "squid-debuginfo-4.9-14.oe1.aarch64.rpm", "squid-debugsource-4.9-14.oe1.aarch64.rpm", "squid-4.9-14.oe1.aarch64.rpm" ], "x86_64": [ "squid-4.9-14.oe1.x86_64.rpm", "squid-debuginfo-4.9-14.oe1.x86_64.rpm", "squid-debugsource-4.9-14.oe1.x86_64.rpm" ], "src": [ "squid-4.9-14.oe1.src.rpm" ] }
{ "aarch64": [ "squid-debuginfo-4.9-14.oe1.aarch64.rpm", "squid-debugsource-4.9-14.oe1.aarch64.rpm", "squid-4.9-14.oe1.aarch64.rpm" ], "x86_64": [ "squid-4.9-14.oe1.x86_64.rpm", "squid-debugsource-4.9-14.oe1.x86_64.rpm", "squid-debuginfo-4.9-14.oe1.x86_64.rpm" ], "src": [ "squid-4.9-14.oe1.src.rpm" ] }
{ "aarch64": [ "squid-debugsource-4.9-18.oe2203.aarch64.rpm", "squid-debuginfo-4.9-18.oe2203.aarch64.rpm", "squid-4.9-18.oe2203.aarch64.rpm", "squid-debugsource-4.9-18.oe2203sp1.aarch64.rpm", "squid-debuginfo-4.9-18.oe2203sp1.aarch64.rpm", "squid-4.9-18.oe2203sp1.aarch64.rpm", "squid-4.9-18.oe2203sp2.aarch64.rpm", "squid-debugsource-4.9-18.oe2203sp2.aarch64.rpm", "squid-debuginfo-4.9-18.oe2203sp2.aarch64.rpm" ], "x86_64": [ "squid-debuginfo-4.9-18.oe2203.x86_64.rpm", "squid-4.9-18.oe2203.x86_64.rpm", "squid-debugsource-4.9-18.oe2203.x86_64.rpm", "squid-debugsource-4.9-18.oe2203sp1.x86_64.rpm", "squid-debuginfo-4.9-18.oe2203sp1.x86_64.rpm", "squid-4.9-18.oe2203sp1.x86_64.rpm", "squid-debuginfo-4.9-18.oe2203sp2.x86_64.rpm", "squid-debugsource-4.9-18.oe2203sp2.x86_64.rpm", "squid-4.9-18.oe2203sp2.x86_64.rpm" ], "src": [ "squid-4.9-18.oe2203.src.rpm", "squid-4.9-18.oe2203sp1.src.rpm", "squid-4.9-18.oe2203sp2.src.rpm" ] }
{ "aarch64": [ "squid-debugsource-4.9-18.oe2203sp1.aarch64.rpm", "squid-debuginfo-4.9-18.oe2203sp1.aarch64.rpm", "squid-4.9-18.oe2203sp1.aarch64.rpm" ], "x86_64": [ "squid-debugsource-4.9-18.oe2203sp1.x86_64.rpm", "squid-debuginfo-4.9-18.oe2203sp1.x86_64.rpm", "squid-4.9-18.oe2203sp1.x86_64.rpm" ], "src": [ "squid-4.9-18.oe2203sp1.src.rpm" ] }
{ "aarch64": [ "squid-4.9-18.oe2203sp2.aarch64.rpm", "squid-debugsource-4.9-18.oe2203sp2.aarch64.rpm", "squid-debuginfo-4.9-18.oe2203sp2.aarch64.rpm" ], "x86_64": [ "squid-debuginfo-4.9-18.oe2203sp2.x86_64.rpm", "squid-debugsource-4.9-18.oe2203sp2.x86_64.rpm", "squid-4.9-18.oe2203sp2.x86_64.rpm" ], "src": [ "squid-4.9-18.oe2203sp2.src.rpm" ] }