Debian Security Advisory
DLA-3151-1 squid -- LTS security update
- Date Reported:
- 13 Oct 2022
- Affected Packages:
- squid
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2022-41317, CVE-2022-41318.
- More information:
-
Multiple vulnerabilities were discovered in squid, a Web Proxy cache
- CVE-2022-41317
Due to inconsistent handling of internal URIs Squid is vulnerable to Exposure of Sensitive Information about clients using the proxy.
- CVE-2022-41318
Due to an incorrect integer overflow protection Squid SSPI and SMB authentication helpers are vulnerable to a Buffer Overflow attack.
For Debian 10 buster, these problems have been fixed in version 4.6-1+deb10u8.
We recommend that you upgrade your squid packages.
For the detailed security status of squid please refer to its security tracker page at: https://security-tracker.debian.org/tracker/squid
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
- CVE-2022-41317