Debian Security Advisory

DLA-3151-1 squid -- LTS security update

Date Reported:
13 Oct 2022
Affected Packages:
squid
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2022-41317, CVE-2022-41318.
More information:

Multiple vulnerabilities were discovered in squid, a Web Proxy cache

  • CVE-2022-41317

    Due to inconsistent handling of internal URIs Squid is vulnerable to Exposure of Sensitive Information about clients using the proxy.

  • CVE-2022-41318

    Due to an incorrect integer overflow protection Squid SSPI and SMB authentication helpers are vulnerable to a Buffer Overflow attack.

For Debian 10 buster, these problems have been fixed in version 4.6-1+deb10u8.

We recommend that you upgrade your squid packages.

For the detailed security status of squid please refer to its security tracker page at: https://security-tracker.debian.org/tracker/squid

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS