[ALSA-2023:6748] Critical: squid security update
Type:
security
Severity:
critical
Release date:
2023-11-14
Description:
Squid is a high-performance proxy caching server for web clients, supporting FTP, Gopher, and HTTP data objects. Security Fix(es): * squid: Denial of Service in HTTP Digest Authentication (CVE-2023-46847) * squid: Request/Response smuggling in HTTP/1.1 and ICAP (CVE-2023-46846) * squid: denial of Service in FTP (CVE-2023-46848) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 squid-5.5-6.el9_3.1.aarch64.rpm 88ab8b3e3dbdbf1951ab9640c12b2bcf58a5c8f4e06452931bea4a1c79b88b62
ppc64le squid-5.5-6.el9_3.1.ppc64le.rpm 087272e3ccf7320ade6f9ee1846cb872eac0ead6c228c5757e2485a89954b423
s390x squid-5.5-6.el9_3.1.s390x.rpm 5e7c56c6f155663f4a664394a04ffa2c554ecb91ae4afd98efcb31786e11d878
x86_64 squid-5.5-6.el9_3.1.x86_64.rpm 0bd303d5751f106cece2e014ea60fa6082ee308bfe7677e56b08dd7e9ac27237
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.