Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Changes with Apache Traffic Server 9.2.9 #12071 - Fix chunked pipelined requests #12075 - Fix send 100 Continue optimization for GET #12077 - Fix intercept plugin ignoring ACL #12079 - ACL combination tests for 9.2.x. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-286e6fc13a 2025-03-14 02:12:06.905953+00:00 -------------------------------------------------------------------------------- Name : trafficserver Product : Fedora 40 Version : 9.2.9 Release : 1.fc40 URL : https://trafficserver.apache.org/ Summary : Fast, scalable and extensible HTTP/1.1 and HTTP/2 caching proxy server Description : Traffic Server is a high-performance building block for cloud services. It's more than just a caching proxy server; it also has support for plugins to build large scale web applications. Key features: Caching - Improve your response time, while reducing server load and bandwidth needs by caching and reusing frequently-requested web pages, images, and web service calls. Proxying - Easily add keep-alive, filter or anonymize content requests, or add load balancing by adding a proxy layer. Fast - Scales well on modern SMP hardware, handling 10s of thousands of requests per second. Extensible - APIs to write your own plug-ins to do anything from modifying HTTP headers to handling ESI requests to writing your own cache algorithm. Proven - Handling over 400TB a day at Yahoo! both as forward and reverse proxies, Apache Traffic Server is battle hardened. -------------------------------------------------------------------------------- Update Information: Changes with Apache Traffic Server 9.2.9 #12071 - Fix chunked pipelined requests #12075 - Fix send 100 Continue optimization for GET #12077 - Fix intercept plugin ignoring ACL #12079 - ACL combination tests for 9.2.x -------------------------------------------------------------------------------- ChangeLog: * WedMar 5 2025 Jered Floyd 9.2.9-1 - Update to upstream 9.2.9 - Resolves CVE-2024-38311, CVE-2024-56195, CVE-2024-56196, CVE-2024-56202 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-286e6fc13a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Several security vulnerabilities have been discovered in Squid, a full featured web proxy cache. Due to programming errors in Squid's HTTP request parsing, remote attackers may be able to execute a denial of service attack by sending large X-Forwarded-For header or trigger a stack buffer overflow while . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5637-1
It was discovered that the fix for CVE-2023-46846 was incomplete. In some cases Squid, a full featured web proxy cache, returned empty responses for URLs when Transfer-Encoding: chunked was in use. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3709-2
An update that solves 5 vulnerabilities and has three fixes is now available. . openSUSE Security Update: Security update for squid ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0879-1 Rating: important References: #1171164 #1171569 #1183436 #1185916 #1185918 #1185919 #1185921 #1185923 Cross-References: CVE-2020-25097 CVE-2021-28651 CVE-2021-28652 CVE-2021-28662 CVE-2021-31806 CVSS scores: CVE-2020-25097 (NVD) : 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N CVE-2020-25097 (SUSE): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N CVE-2021-28651 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-28651 (SUSE): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H CVE-2021-28652 (NVD) : 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H CVE-2021-28652 (SUSE): 6.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H CVE-2021-28662 (NVD) : 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2021-28662 (SUSE): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2021-31806 (NVD) : 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVE-2021-31806 (SUSE): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that solves 5 vulnerabilities and has three fixes is now available. Description: This update for squid fixes the following issues: - update to 4.15: - CVE-2021-28652: Broken cache manager URL parsing (bsc#1185918) - CVE-2021-28651: Memory leak in RFC 2169 response parsing (bsc#1185921) - CVE-2021-28662: Limit HeaderLookupTable_t::lookup() to BadHdr and specific IDs (bsc#1185919) - CVE-2021-31806: Handle moreRange requests (bsc#1185916) - CVE-2020-25097: HTTP Request Smuggling vulnerability (bsc#1183436) - Handle more partial responses (bsc#1185923) - fix previous change to reinstante permissions macros, because the wrong path has been used (bsc#1171569). - use libexecdir instead of libdir to conform to recent changes in Factory (bsc#1171164). - Reinstate permissions macros for pinger binary, because the permissions package is also responsible for setting up the cap_net_raw capability, currently a fresh squid install doesn't get a capability bit at all (bsc#1171569). - Change pinger and basic_pam_auth helper to use standard permissions. pinger uses cap_net_raw=ep instead (bsc#1171569) This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-879=1 Package List: - openSUSE Leap 15.2 (x86_64): squid-4.15-lp152.2.9.1 squid-debuginfo-4.15-lp152.2.9.1 squid-debugsource-4.15-lp152.2.9.1 References: https://www.suse.com/security/cve/CVE-2020-25097.html https://www.suse.com/security/cve/CVE-2021-28651.html https://www.suse.com/security/cve/CVE-2021-28652.html https://www.suse.com/security/cve/CVE-2021-28662.html https://www.suse.com/security/cve/CVE-2021-31806.html https://bugzilla.suse.com/1171164 https://bugzilla.suse.com/1171569 https://bugzilla.suse.com/1183436 https://bugzilla.suse.com/1185916 https://bugzilla.suse.com/1185918 https://bugzilla.suse.com/1185919 https://bugzilla.suse.com/1185921 https://bugzilla.suse.com/1185923 . A crucial patch release for squid on openSUSE addresses various concerns and incorporates solutions for several security flaws.. openSUSE 15.2 Security Update, Squid MemoryLeak Fix, Important Squid Patch. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in Squid.. =========================================================================Ubuntu Security Notice USN-4356-1 May 13, 2020 squid, squid3 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 19.10 - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Squid. Software Description: - squid: Web proxy cache server - squid3: Web proxy cache server Details: Jeriko One discovered that Squid incorrectly handled certain Edge Side Includes (ESI) responses. A malicious remote server could cause Squid to crash, possibly poison the cache, or possibly execute arbitrary code. (CVE-2019-12519, CVE-2019-12521) It was discovered that Squid incorrectly handled the hostname parameter to cachemgr.cgi when certain browsers are used. A remote attacker could possibly use this issue to inject HTML or invalid characters in the hostname parameter. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 19.10. (CVE-2019-18860) Clément Berthaux and Florian Guilbert discovered that Squid incorrectly handled Digest Authentication nonce values. A remote attacker could use this issue to replay nonce values, or possibly execute arbitrary code. (CVE-2020-11945) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: squid 4.10-1ubuntu1.1 Ubuntu 19.10: squid 4.8-1ubuntu2.3 Ubuntu 18.04 LTS: squid 3.5.27-1ubuntu1.6 Ubuntu 16.04 LTS: squid 3.5.12-1ubuntu7.11 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4356-1 CVE-2019-12519, CVE-2019-12521, CVE-2019-18860, CVE-2020-11945 PackageInformation: https://launchpad.net/ubuntu/+source/squid/4.10-1ubuntu1.1 https://launchpad.net/ubuntu/+source/squid/4.8-1ubuntu2.3 https://launchpad.net/ubuntu/+source/squid3/3.5.27-1ubuntu1.6 https://launchpad.net/ubuntu/+source/squid3/3.5.12-1ubuntu7.11 . Multiple vulnerabilities addressed in Squid impacting Ubuntu LTS versions. It's advised to perform updates for enhanced system protection.. Squid Security, Ubuntu 20.04, Web Proxy Updates, Ubuntu Security Notices. . LinuxSecurity.com Team
Multiple vulnerabilities have been found in Squid, the worst of which could result in the arbitrary execution of code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202005-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Squid: Multiple vulnerabilities Date: May 12, 2020 Bugs: #719046 ID: 202005-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Squid, the worst of which could result in the arbitrary execution of code. Background ========= Squid is a full-featured Web proxy cache designed to run on Unix systems. It supports proxying and caching of HTTP, FTP, and other URLs, as well as SSL support, cache hierarchies, transparent caching, access control lists and many other features. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-proxy/squid < 4.11 > = 4.11 Description ========== Multiple vulnerabilities have been discovered in Squid. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All Squid users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-proxy/squid-4.11" References ========= [ 1 ] CVE-2019-12519 https://nvd.nist.gov/vuln/detail/CVE-2019-12519 [ 2 ] CVE-2019-12521 https://nvd.nist.gov/vuln/detail/CVE-2019-12521 [ 3 ] CVE-2020-11945 https://nvd.nist.gov/vuln/detail/CVE-2020-11945 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202005-05 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Multiple vulnerabilities have been found in Squid, the worst of which could lead to arbitrary code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202003-34 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Squid: Multiple vulnerabilities Date: March 16, 2020 Bugs: #699854, #708296 ID: 202003-34 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Squid, the worst of which could lead to arbitrary code execution. Background ========= Squid is a full-featured Web proxy cache designed to run on Unix systems. It supports proxying and caching of HTTP, FTP, and other URLs, as well as SSL support, cache hierarchies, transparent caching, access control lists and many other features. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-proxy/squid < 4.10 > = 4.10 Description ========== Multiple vulnerabilities have been discovered in Squid. Please review the CVE identifiers referenced below for details. Impact ===== A remote attacker, by sending a specially crafted request, could possibly execute arbitrary code with the privileges of the process, obtain sensitive information or cause a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All Squid users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-proxy/squid-4.10" References ========= [ 1 ] CVE-2019-12526 https://nvd.nist.gov/vuln/detail/CVE-2019-12526 [ 2 ] CVE-2019-12528 https://nvd.nist.gov/vuln/detail/CVE-2019-12528 [ 3 ] CVE-2019-18678 https://nvd.nist.gov/vuln/detail/CVE-2019-18678 [ 4 ] CVE-2019-18679 https://nvd.nist.gov/vuln/detail/CVE-2019-18679 [ 5 ] CVE-2020-8449 https://nvd.nist.gov/vuln/detail/CVE-2020-8449 [ 6 ] CVE-2020-8450 https://nvd.nist.gov/vuln/detail/CVE-2020-8450 [ 7 ] CVE-2020-8517 https://nvd.nist.gov/vuln/detail/CVE-2020-8517 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202003-34 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
An updated squid package that fixes one security issue is now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: squid security update Advisory ID: RHSA-2011:1791-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2011:1791.html Issue date: 2011-12-06 CVE Names: CVE-2011-4096 ==================================================================== 1. Summary: An updated squid package that fixes one security issue is now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 3. Description: Squid is a high-performance proxy caching server for web clients, supporting FTP, Gopher, and HTTP data objects. An input validation flaw was found in the way Squid calculated the total number of resource records in the answer section of multiple name server responses. An attacker could use this flaw to cause Squid to crash. (CVE-2011-4096) Users of squid should upgrade to this updated package, which contains a backported patch to correct this issue. After installing this update, the squid service will be restarted automatically. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to usethe Red Hat Network to apply this update are available at https://access.redhat.com/kb/docs/DOC-11259 5. Bugs fixed (http://bugzilla.redhat.com/): 750316 - CVE-2011-4096 squid: Invalid free by processing CNAME DNS record pointing to another CNAME record pointing to an empty A-record 6. Package List: Red Hat Enterprise Linux Server (v. 6): Source: i386: squid-3.1.10-1.el6_2.1.i686.rpm squid-debuginfo-3.1.10-1.el6_2.1.i686.rpm ppc64: squid-3.1.10-1.el6_2.1.ppc64.rpm squid-debuginfo-3.1.10-1.el6_2.1.ppc64.rpm s390x: squid-3.1.10-1.el6_2.1.s390x.rpm squid-debuginfo-3.1.10-1.el6_2.1.s390x.rpm x86_64: squid-3.1.10-1.el6_2.1.x86_64.rpm squid-debuginfo-3.1.10-1.el6_2.1.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 6): Source: i386: squid-3.1.10-1.el6_2.1.i686.rpm squid-debuginfo-3.1.10-1.el6_2.1.i686.rpm x86_64: squid-3.1.10-1.el6_2.1.x86_64.rpm squid-debuginfo-3.1.10-1.el6_2.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/#package 7. References: https://access.redhat.com/security/cve/CVE-2011-4096 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2011 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFO3okaXlSAg2UNWIIRAugUAJ48SoKaJnBIdV3VuU2LnoNJduKCPQCgl16T 0qMU+uAlo+8SMzhx+aS6EuE=tyE7 -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
Get the latest Linux and open source security news straight to your inbox.