Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Debian 9: DLA-2598-1 Critical Squid3 HTTP Request Smuggling Alert

debian lts
Calendar Grey March 18, 2021
Dist Debian Esm H88
The latest Squid3 patch for Debian LTS tackles critical HTTP request smuggling flaws. Users advised to upgrade for improved protection.
Due to improper input validation, Squid is vulnerable to an HTTP Request Smuggling attack

Summary

This problem allows a trusted client to perform HTTP Request
Smuggling and access services otherwise forbidden by Squid
security controls.

For Debian 9 stretch, this problem has been fixed in version
3.5.23-5+deb9u6.

We recommend that you upgrade your squid3 packages.

For the detailed security status of squid3 please refer to
its security tracker page at:

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

Package: squid3
Version: 3.5.23-5+deb9u6
CVE ID: CVE-2020-25097
Debian Bug: 985068

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here