RHSA-2024:11049: Important: squid security update
Important: squid security update
Other sources
Squid is a high-performance proxy caching server for web clients, supporting FTP, Gopher, and HTTP data objects.<br>Security Fix(es):<br><li> squid: Request/Response smuggling in HTTP/1.1 and ICAP (CVE-2023-46846)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:11049?
The severity of RHSA-2024:11049 is classified as important.
What does CVE-2023-46846 in RHSA-2024:11049 refer to?
CVE-2023-46846 refers to a vulnerability involving request/response smuggling in HTTP/1.1 and ICAP in Squid.
How do I fix RHSA-2024:11049?
To fix RHSA-2024:11049, upgrade your Squid package to version 3.5.20-17.el7_9.13 or later.
Which systems are affected by RHSA-2024:11049?
RHSA-2024:11049 affects various versions of Red Hat Enterprise Linux Server that include the Squid package.
Is there a workaround for the vulnerability in RHSA-2024:11049?
There are no specific workarounds recommended for the vulnerability; applying the update is the suggested action.