RHSA-2024:0046: Important: squid:4 security update
Important: squid:4 security update
Other sources
Squid is a high-performance proxy caching server for web clients, supporting FTP, Gopher, and HTTP data objects.Security Fix(es): squid: Denial of Service in SSL Certificate validation (CVE-2023-46724) squid: NULL pointer dereference in the gopher protocol code (CVE-2023-46728) squid: Buffer over-read in the HTTP Message processing feature (CVE-2023-49285) squid: Incorrect Check of Function Return Value In Helper Process management (CVE-2023-49286) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What security issues are addressed in RHSA-2024:0046?
RHSA-2024:0046 addresses a Denial of Service vulnerability in SSL certificate validation and other issues in Squid.
How do I fix the vulnerabilities outlined in RHSA-2024:0046?
To fix the vulnerabilities in RHSA-2024:0046, update your Squid and libecap packages to the recommended versions 4.15-7.module+el8.9.0+20975+25f17541.5 or later and 1.0.1-2.module+el8.9.0+19703+a1da7223 or later.
What is the severity level of RHSA-2024:0046?
The severity level of RHSA-2024:0046 is categorized as important.
Which systems are affected by the RHSA-2024:0046 vulnerability?
Affected systems include Red Hat Enterprise Linux for x86_64, ARM 64, Power, and IBM z Systems.
Are there any specific packages in RHSA-2024:0046 that need immediate attention?
Yes, the Squid package version 4.15-7.module+el8.9.0+20975+25f17541.5 and libecap version 1.0.1-2.module+el8.9.0+19703+a1da7223 are critical and should be updated.