Debian Security Advisory

DSA-4507-1 squid -- security update

Date Reported:
24 Aug 2019
Affected Packages:
squid
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 931478.
In Mitre's CVE dictionary: CVE-2019-12525, CVE-2019-12527, CVE-2019-12529, CVE-2019-12854, CVE-2019-13345.
More information:

Several vulnerabilities were discovered in Squid, a fully featured web proxy cache. The flaws in the HTTP Digest Authentication processing, the HTTP Basic Authentication processing and in the cachemgr.cgi allowed remote attackers to perform denial of service and cross-site scripting attacks, and potentially the execution of arbitrary code.

For the stable distribution (buster), these problems have been fixed in version 4.6-1+deb10u1.

We recommend that you upgrade your squid packages.

For the detailed security status of squid please refer to its security tracker page at: https://security-tracker.debian.org/tracker/squid