RHSA-2024:1153: Important: squid security update
Important: squid security update
Other sources
Squid is a high-performance proxy caching server for web clients, supporting FTP, and HTTP data objects.<br>Security Fix(es):<br><li> squid: DoS against HTTP and HTTPS (CVE-2023-5824)</li> <li> squid: Denial of Service in SSL Certificate validation (CVE-2023-46724)</li> <li> squid: NULL pointer dereference in the gopher protocol code (CVE-2023-46728)</li> <li> squid: Buffer over-read in the HTTP Message processing feature (CVE-2023-49285)</li> <li> squid: Incorrect Check of Function Return Value In Helper Process management (CVE-2023-49286)</li> <li> squid: denial of service in HTTP request parsing (CVE-2023-50269)</li> Bug Fix(es):<br><li> squid crashes in assertion when a parent peer exists (RHEL-18248)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:1153?
RHSA-2024:1153 has been classified as important due to its potential impact on the operation of affected systems.
How do I fix RHSA-2024:1153?
To fix RHSA-2024:1153, update your Squid package to version 5.2-1.el9_0.4 or later.
What vulnerabilities does RHSA-2024:1153 address?
RHSA-2024:1153 addresses vulnerabilities including a Denial of Service (DoS) risk in HTTP and HTTPS handling and SSL certificate validation.
Which versions of Squid are affected by RHSA-2024:1153?
RHSA-2024:1153 affects versions of Squid prior to 5.2-1.el9_0.4.
Is a reboot required after applying the update for RHSA-2024:1153?
A reboot is not required after applying the update for RHSA-2024:1153, but it is recommended to restart the Squid service.