RHSA-2024:0771: Important: squid:4 security update
Important: squid:4 security update
Other sources
Squid is a high-performance proxy caching server for web clients, supporting FTP, and HTTP data objects.Security Fix(es): squid: DoS against HTTP and HTTPS (CVE-2023-5824) squid: Denial of Service in SSL Certificate validation (CVE-2023-46724) squid: NULL pointer dereference in the gopher protocol code (CVE-2023-46728) squid: Buffer over-read in the HTTP Message processing feature (CVE-2023-49285) squid: Incorrect Check of Function Return Value In Helper Process management (CVE-2023-49286) squid: denial of service in HTTP request parsing (CVE-2023-50269) Bug Fix(es): squid crashes in assertion when a parent peer exists (RHEL-18255) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libecapto a version that resolves this vulnerability.Fixed in 1.0.1-2.module+el8.1.0+4044+36416a77 - Upgrade
Upgrade
redhat/squidto a version that resolves this vulnerability.Fixed in 4.15-3.module+el8.6.0+21069+a1561e3d.4 - Upgrade
Upgrade
redhat/libecap-debuginfoto a version that resolves this vulnerability.Fixed in 1.0.1-2.module+el8.1.0+4044+36416a77 - Upgrade
Upgrade
redhat/libecap-debugsourceto a version that resolves this vulnerability.Fixed in 1.0.1-2.module+el8.1.0+4044+36416a77 - Upgrade
Upgrade
redhat/libecap-develto a version that resolves this vulnerability.Fixed in 1.0.1-2.module+el8.1.0+4044+36416a77 - Upgrade
Upgrade
redhat/squid-debuginfoto a version that resolves this vulnerability.Fixed in 4.15-3.module+el8.6.0+21069+a1561e3d.4 - Upgrade
Upgrade
redhat/squid-debugsourceto a version that resolves this vulnerability.Fixed in 4.15-3.module+el8.6.0+21069+a1561e3d.4 - Upgrade
Upgrade
redhat/libecapto a version that resolves this vulnerability.Fixed in 1.0.1-2.module+el8.1.0+4044+36416a77.aa - Upgrade
Upgrade
redhat/libecap-debuginfoto a version that resolves this vulnerability.Fixed in 1.0.1-2.module+el8.1.0+4044+36416a77.aa - Upgrade
Upgrade
redhat/libecap-debugsourceto a version that resolves this vulnerability.Fixed in 1.0.1-2.module+el8.1.0+4044+36416a77.aa - Upgrade
Upgrade
redhat/libecap-develto a version that resolves this vulnerability.Fixed in 1.0.1-2.module+el8.1.0+4044+36416a77.aa - Upgrade
Upgrade
redhat/squidto a version that resolves this vulnerability.Fixed in 4.15-3.module+el8.6.0+21069+a1561e3d.4.aa - Upgrade
Upgrade
redhat/squid-debuginfoto a version that resolves this vulnerability.Fixed in 4.15-3.module+el8.6.0+21069+a1561e3d.4.aa - Upgrade
Upgrade
redhat/squid-debugsourceto a version that resolves this vulnerability.Fixed in 4.15-3.module+el8.6.0+21069+a1561e3d.4.aa - Upgrade
Upgrade
squidto a version that resolves this vulnerability.Patch RHEL-18255 - Upgrade
Upgrade
squidto a version that resolves this vulnerability.Patch CVE-2023-49285 - Upgrade
Upgrade
squidto a version that resolves this vulnerability.Patch CVE-2023-46724 - Upgrade
Upgrade
squidto a version that resolves this vulnerability.Patch CVE-2023-49286 - Upgrade
Upgrade
squidto a version that resolves this vulnerability.Patch CVE-2023-46728 - Upgrade
Upgrade
squidto a version that resolves this vulnerability.Patch CVE-2023-50269 - Upgrade
Upgrade
squidto a version that resolves this vulnerability.Patch CVE-2023-5824 - Operational
After installing this update (squid:4 security update), the squid service will be restarted automatically.
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:0771?
The severity of RHSA-2024:0771 is classified as important.
What vulnerabilities are addressed in RHSA-2024:0771?
RHSA-2024:0771 addresses CVE-2023-5824 which involves a denial of service against HTTP and HTTPS as well as a denial of service in SSL certificate validation.
How do I fix RHSA-2024:0771?
To fix RHSA-2024:0771, update to the latest versions of squid and libecap specified in the advisory.
Which versions of squid are affected by RHSA-2024:0771?
Versions of squid below 4.15-3.module+el8.6.0+21069+a1561e3d.4 are affected by RHSA-2024:0771.
Which systems are vulnerable according to RHSA-2024:0771?
RHSA-2024:0771 affects multiple Red Hat Enterprise Linux versions including x86_64, ARM 64, and IBM z Systems.