[ALSA-2024:0046] squid:4 security update
Severity
Important
Affected Packages
6
CVEs
4
squid:4 security update
Squid is a high-performance proxy caching server for web clients, supporting FTP, Gopher, and HTTP data objects.
Security Fix(es):
- squid: Denial of Service in SSL Certificate validation (CVE-2023-46724)
- squid: NULL pointer dereference in the gopher protocol code (CVE-2023-46728)
- squid: Buffer over-read in the HTTP Message processing feature (CVE-2023-49285)
- squid: Incorrect Check of Function Return Value In Helper Process management (CVE-2023-49286)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Package | Affected Version |
---|---|
pkg:rpm/almalinux/squid?arch=x86_64&distro=almalinux-8.9 | < 4.15-7.module_el8.9.0+3708+6acaac63.5 |
pkg:rpm/almalinux/squid?arch=aarch64&distro=almalinux-8.9 | < 4.15-7.module_el8.9.0+3708+6acaac63.5 |
pkg:rpm/almalinux/libecap?arch=x86_64&distro=almalinux-8.6 | < 1.0.1-2.module_el8.6.0+2741+01592ae8 |
pkg:rpm/almalinux/libecap?arch=aarch64&distro=almalinux-8.6 | < 1.0.1-2.module_el8.6.0+2741+01592ae8 |
pkg:rpm/almalinux/libecap-devel?arch=x86_64&distro=almalinux-8.6 | < 1.0.1-2.module_el8.6.0+2741+01592ae8 |
pkg:rpm/almalinux/libecap-devel?arch=aarch64&distro=almalinux-8.6 | < 1.0.1-2.module_el8.6.0+2741+01592ae8 |
- ID
- ALSA-2024:0046
- Severity
- important
- URL
- https://errata.almalinux.org/ALSA-2024:0046.html
- Published
-
2024-01-03T00:00:00
(8 months ago) - Modified
-
2024-01-08T14:59:53
(8 months ago) - Rights
- Copyright 2024 AlmaLinux OS
- Other Advisories
-
- ALAS-2023-1885
- ALAS-2023-1886
- ALAS-2024-1901
- ALAS2-2023-2354
- ALAS2-2024-2381
- ALAS2-2024-2500
- ALPINE:CVE-2023-46724
- ALPINE:CVE-2023-49285
- ALPINE:CVE-2023-49286
- ALSA-2024:0071
- DSA-5637-1
- ELSA-2024-0046
- ELSA-2024-0071
- ELSA-2024-1787
- FEDORA-2023-6317eaa767
- FEDORA-2023-ab77331a34
- RHSA-2024:0046
- RHSA-2024:0071
- RHSA-2024:1787
- SUSE-SU-2023:4380-1
- SUSE-SU-2023:4381-1
- SUSE-SU-2023:4384-1
- SUSE-SU-2023:4544-1
- SUSE-SU-2023:4545-1
- SUSE-SU-2023:4589-1
- SUSE-SU-2023:4698-1
- SUSE-SU-2023:4724-1
- SUSE-SU-2023:4825-1
- USN-6500-1
- USN-6500-2
- USN-6594-1
- USN-6857-1
Source | # ID | Name | URL |
---|---|---|---|
RHSA | RHSA-2024:0046 | https://access.redhat.com/errata/RHSA-2024:0046 | |
CVE | CVE-2023-46724 | https://access.redhat.com/security/cve/CVE-2023-46724 | |
CVE | CVE-2023-46728 | https://access.redhat.com/security/cve/CVE-2023-46728 | |
CVE | CVE-2023-49285 | https://access.redhat.com/security/cve/CVE-2023-49285 | |
CVE | CVE-2023-49286 | https://access.redhat.com/security/cve/CVE-2023-49286 | |
Bugzilla | 2247567 | https://bugzilla.redhat.com/2247567 | |
Bugzilla | 2248521 | https://bugzilla.redhat.com/2248521 | |
Bugzilla | 2252923 | https://bugzilla.redhat.com/2252923 | |
Bugzilla | 2252926 | https://bugzilla.redhat.com/2252926 | |
Self | ALSA-2024:0046 | https://errata.almalinux.org/8/ALSA-2024-0046.html |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/almalinux/squid?arch=x86_64&distro=almalinux-8.9 | almalinux | squid | < 4.15-7.module_el8.9.0+3708+6acaac63.5 | almalinux-8.9 | x86_64 | |
Affected | pkg:rpm/almalinux/squid?arch=aarch64&distro=almalinux-8.9 | almalinux | squid | < 4.15-7.module_el8.9.0+3708+6acaac63.5 | almalinux-8.9 | aarch64 | |
Affected | pkg:rpm/almalinux/libecap?arch=x86_64&distro=almalinux-8.6 | almalinux | libecap | < 1.0.1-2.module_el8.6.0+2741+01592ae8 | almalinux-8.6 | x86_64 | |
Affected | pkg:rpm/almalinux/libecap?arch=aarch64&distro=almalinux-8.6 | almalinux | libecap | < 1.0.1-2.module_el8.6.0+2741+01592ae8 | almalinux-8.6 | aarch64 | |
Affected | pkg:rpm/almalinux/libecap-devel?arch=x86_64&distro=almalinux-8.6 | almalinux | libecap-devel | < 1.0.1-2.module_el8.6.0+2741+01592ae8 | almalinux-8.6 | x86_64 | |
Affected | pkg:rpm/almalinux/libecap-devel?arch=aarch64&distro=almalinux-8.6 | almalinux | libecap-devel | < 1.0.1-2.module_el8.6.0+2741+01592ae8 | almalinux-8.6 | aarch64 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |