- ------------------------------------------------------------------------- Debian LTS Advisory DLA-3151-1 [email protected] https://www.debian.org/lts/security/ Abhijith PA October 13, 2022 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : squid Version : 4.6-1+deb10u8 CVE ID : CVE-2022-41317 CVE-2022-41318 Multiple vulnerabilities were discovered in squid, a Web Proxy cache CVE-2022-41317 Due to inconsistent handling of internal URIs Squid is vulnerable to Exposure of Sensitive Information about clients using the proxy. CVE-2022-41318 Due to an incorrect integer overflow protection Squid SSPI and SMB authentication helpers are vulnerable to a Buffer Overflow attack. For Debian 10 buster, these problems have been fixed in version 4.6-1+deb10u8. We recommend that you upgrade your squid packages. For the detailed security status of squid please refer to its security tracker page at: https://security-tracker.debian.org/tracker/squid Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS