[USN-6857-1] Squid vulnerabilities

Severity High
Affected Packages 12
CVEs 6

Several security issues were fixed in Squid.

Joshua Rogers discovered that Squid incorrectly handled requests with the
urn: scheme. A remote attacker could possibly use this issue to cause
Squid to consume resources, leading to a denial of service. This issue
only affected Ubuntu 16.04 LTS. (CVE-2021-28651)

It was discovered that Squid incorrectly handled SSPI and SMB
authentication. A remote attacker could use this issue to cause Squid to
crash, resulting in a denial of service, or possibly obtain sensitive
information. This issue only affected Ubuntu 16.04 LTS. (CVE-2022-41318)

Joshua Rogers discovered that Squid incorrectly handled HTTP message
processing. A remote attacker could possibly use this issue to cause
Squid to crash, resulting in a denial of service. (CVE-2023-49285)

Joshua Rogers discovered that Squid incorrectly handled Helper process
management. A remote attacker could possibly use this issue to cause
Squid to crash, resulting in a denial of service. (CVE-2023-49286)

Joshua Rogers discovered that Squid incorrectly handled HTTP request
parsing. A remote attacker could possibly use this issue to cause
Squid to crash, resulting in a denial of service.
(CVE-2023-50269, CVE-2024-25617)

Package Affected Version
pkg:deb/ubuntu/squidclient?distro=xenial < 3.5.12-1ubuntu7.16+esm3
pkg:deb/ubuntu/squidclient?distro=bionic < 3.5.27-1ubuntu1.14+esm2
pkg:deb/ubuntu/squid?distro=xenial < 3.5.12-1ubuntu7.16+esm3
pkg:deb/ubuntu/squid?distro=bionic < 3.5.27-1ubuntu1.14+esm2
pkg:deb/ubuntu/squid3?distro=xenial < 3.5.12-1ubuntu7.16+esm3
pkg:deb/ubuntu/squid3?distro=bionic < 3.5.27-1ubuntu1.14+esm2
pkg:deb/ubuntu/squid-purge?distro=xenial < 3.5.12-1ubuntu7.16+esm3
pkg:deb/ubuntu/squid-purge?distro=bionic < 3.5.27-1ubuntu1.14+esm2
pkg:deb/ubuntu/squid-common?distro=xenial < 3.5.12-1ubuntu7.16+esm3
pkg:deb/ubuntu/squid-common?distro=bionic < 3.5.27-1ubuntu1.14+esm2
pkg:deb/ubuntu/squid-cgi?distro=xenial < 3.5.12-1ubuntu7.16+esm3
pkg:deb/ubuntu/squid-cgi?distro=bionic < 3.5.27-1ubuntu1.14+esm2
ID
USN-6857-1
Severity
high
Severity from
CVE-2022-41318
URL
https://ubuntu.com/security/notices/USN-6857-1
Published
2024-06-27T10:48:19
(2 months ago)
Modified
2024-06-27T10:48:19
(2 months ago)
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/squidclient?distro=xenial ubuntu squidclient < 3.5.12-1ubuntu7.16+esm3 xenial
Affected pkg:deb/ubuntu/squidclient?distro=bionic ubuntu squidclient < 3.5.27-1ubuntu1.14+esm2 bionic
Affected pkg:deb/ubuntu/squid?distro=xenial ubuntu squid < 3.5.12-1ubuntu7.16+esm3 xenial
Affected pkg:deb/ubuntu/squid?distro=bionic ubuntu squid < 3.5.27-1ubuntu1.14+esm2 bionic
Affected pkg:deb/ubuntu/squid3?distro=xenial ubuntu squid3 < 3.5.12-1ubuntu7.16+esm3 xenial
Affected pkg:deb/ubuntu/squid3?distro=bionic ubuntu squid3 < 3.5.27-1ubuntu1.14+esm2 bionic
Affected pkg:deb/ubuntu/squid-purge?distro=xenial ubuntu squid-purge < 3.5.12-1ubuntu7.16+esm3 xenial
Affected pkg:deb/ubuntu/squid-purge?distro=bionic ubuntu squid-purge < 3.5.27-1ubuntu1.14+esm2 bionic
Affected pkg:deb/ubuntu/squid-common?distro=xenial ubuntu squid-common < 3.5.12-1ubuntu7.16+esm3 xenial
Affected pkg:deb/ubuntu/squid-common?distro=bionic ubuntu squid-common < 3.5.27-1ubuntu1.14+esm2 bionic
Affected pkg:deb/ubuntu/squid-cgi?distro=xenial ubuntu squid-cgi < 3.5.12-1ubuntu7.16+esm3 xenial
Affected pkg:deb/ubuntu/squid-cgi?distro=bionic ubuntu squid-cgi < 3.5.27-1ubuntu1.14+esm2 bionic
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...