[ALSA-2024:0071] squid security update
Severity
Important
Affected Packages
2
CVEs
4
squid security update
Squid is a high-performance proxy caching server for web clients, supporting FTP, Gopher, and HTTP data objects.
Security Fix(es):
- squid: Denial of Service in SSL Certificate validation (CVE-2023-46724)
- squid: NULL pointer dereference in the gopher protocol code (CVE-2023-46728)
- squid: Buffer over-read in the HTTP Message processing feature (CVE-2023-49285)
- squid: Incorrect Check of Function Return Value In Helper Process management (CVE-2023-49286)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Package | Affected Version |
---|---|
pkg:rpm/almalinux/squid?arch=x86_64&distro=almalinux-9.3 | < 5.5-6.el9_3.5 |
pkg:rpm/almalinux/squid?arch=aarch64&distro=almalinux-9.3 | < 5.5-6.el9_3.5 |
- ID
- ALSA-2024:0071
- Severity
- important
- URL
- https://errata.almalinux.org/ALSA-2024:0071.html
- Published
-
2024-01-08T00:00:00
(8 months ago) - Modified
-
2024-01-08T13:54:39
(8 months ago) - Rights
- Copyright 2024 AlmaLinux OS
- Other Advisories
-
- ALAS-2023-1885
- ALAS-2023-1886
- ALAS-2024-1901
- ALAS2-2023-2354
- ALAS2-2024-2381
- ALAS2-2024-2500
- ALPINE:CVE-2023-46724
- ALPINE:CVE-2023-49285
- ALPINE:CVE-2023-49286
- ALSA-2024:0046
- DSA-5637-1
- ELSA-2024-0046
- ELSA-2024-0071
- ELSA-2024-1787
- FEDORA-2023-6317eaa767
- FEDORA-2023-ab77331a34
- RHSA-2024:0046
- RHSA-2024:0071
- RHSA-2024:1787
- SUSE-SU-2023:4380-1
- SUSE-SU-2023:4381-1
- SUSE-SU-2023:4384-1
- SUSE-SU-2023:4544-1
- SUSE-SU-2023:4545-1
- SUSE-SU-2023:4589-1
- SUSE-SU-2023:4698-1
- SUSE-SU-2023:4724-1
- SUSE-SU-2023:4825-1
- USN-6500-1
- USN-6500-2
- USN-6594-1
- USN-6857-1
Source | # ID | Name | URL |
---|---|---|---|
RHSA | RHSA-2024:0071 | https://access.redhat.com/errata/RHSA-2024:0071 | |
CVE | CVE-2023-46724 | https://access.redhat.com/security/cve/CVE-2023-46724 | |
CVE | CVE-2023-46728 | https://access.redhat.com/security/cve/CVE-2023-46728 | |
CVE | CVE-2023-49285 | https://access.redhat.com/security/cve/CVE-2023-49285 | |
CVE | CVE-2023-49286 | https://access.redhat.com/security/cve/CVE-2023-49286 | |
Bugzilla | 2247567 | https://bugzilla.redhat.com/2247567 | |
Bugzilla | 2248521 | https://bugzilla.redhat.com/2248521 | |
Bugzilla | 2252923 | https://bugzilla.redhat.com/2252923 | |
Bugzilla | 2252926 | https://bugzilla.redhat.com/2252926 | |
Self | ALSA-2024:0071 | https://errata.almalinux.org/9/ALSA-2024-0071.html |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/almalinux/squid?arch=x86_64&distro=almalinux-9.3 | almalinux | squid | < 5.5-6.el9_3.5 | almalinux-9.3 | x86_64 | |
Affected | pkg:rpm/almalinux/squid?arch=aarch64&distro=almalinux-9.3 | almalinux | squid | < 5.5-6.el9_3.5 | almalinux-9.3 | aarch64 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |