Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Debian 11: DLA-3910-1 urgent: apache remote execution exposure

debian lts
Calendar Grey January 9, 2024
Dist Debian Esm H88
Debian LTS Advisory DLA-3709-1 details critical fixes for vulnerabilities in Squid affecting remote execution.
Several security vulnerabilities have been discovered in Squid, a full featured web proxy cache

Summary

In regard to CVE-2023-46728: Please note that support for the Gopher protocol
has simply been removed in future Squid versions. There are no plans by the
upstream developers of Squid to fix this issue. We recommend to reject all
Gopher URL requests instead.

For Debian 10 buster, these problems have been fixed in version
4.6-1+deb10u9.

We recommend that you upgrade your squid packages.

For the detailed security status of squid please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/squid

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

Package: squid
Version: 4.6-1+deb10u9
CVE ID: CVE-2023-46846 CVE-2023-46847 CVE-2023-49285 CVE-2023-49286
Debian Bug: 1054537 1055250 1058721

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here