DSA-4507-1 squid -- security update

Related Vulnerabilities: CVE-2019-12525   CVE-2019-12527   CVE-2019-12529   CVE-2019-12854   CVE-2019-13345  

Several vulnerabilities were discovered in Squid, a fully featured web proxy cache. The flaws in the HTTP Digest Authentication processing, the HTTP Basic Authentication processing and in the cachemgr.cgi allowed remote attackers to perform denial of service and cross-site scripting attacks, and potentially the execution of arbitrary code. For the stable distribution (buster), these problems have been fixed in version 4.6-1+deb10u1. We recommend that you upgrade your squid packages. For the detailed security status of squid please refer to its security tracker page at: https://security-tracker.debian.org/tracker/squid

Debian Security Advisory

DSA-4507-1 squid -- security update

Date Reported:
24 Aug 2019
Affected Packages:
squid
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 931478.
In Mitre's CVE dictionary: CVE-2019-12525, CVE-2019-12527, CVE-2019-12529, CVE-2019-12854, CVE-2019-13345.
More information:

Several vulnerabilities were discovered in Squid, a fully featured web proxy cache. The flaws in the HTTP Digest Authentication processing, the HTTP Basic Authentication processing and in the cachemgr.cgi allowed remote attackers to perform denial of service and cross-site scripting attacks, and potentially the execution of arbitrary code.

For the stable distribution (buster), these problems have been fixed in version 4.6-1+deb10u1.

We recommend that you upgrade your squid packages.

For the detailed security status of squid please refer to its security tracker page at: https://security-tracker.debian.org/tracker/squid