Information on source package squid3

Available versions

ReleaseVersion
jessie3.5.23-5+deb8u7
stretch3.5.23-5+deb9u10
stretch (security)3.5.23-5+deb9u7

Open issues

BugjessiestretchDescription
CVE-2024-25617vulnerablevulnerableSquid is an open source caching proxy for the Web supporting HTTP, HTT ...
CVE-2024-25111vulnerablevulnerableSquid is a web proxy cache. Starting in version 3.5.27 and prior to ve ...
CVE-2023-49288vulnerablevulnerableSquid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and ...
CVE-2023-46846vulnerablevulnerableSQUID is vulnerable to HTTP request smuggling, caused by chunked decod ...
CVE-2023-5824vulnerablevulnerableSquid is vulnerable to Denial of Service attack against HTTP and HTTPS ...

Open unimportant issues

BugjessiestretchDescription
CVE-2020-14058vulnerablevulnerableAn issue was discovered in Squid before 4.12 and 5.x before 5.0.3. Due ...
CVE-2020-8517vulnerablevulnerableAn issue was discovered in Squid before 4.10. Due to incorrect input v ...
CVE-2019-12522vulnerablevulnerableAn issue was discovered in Squid through 4.7. When Squid is run as roo ...
CVE-2018-19131vulnerablevulnerableSquid before 4.4 has XSS via a crafted X.509 certificate during HTTP(S ...
CVE-2018-1172vulnerablevulnerableThis vulnerability allows remote attackers to deny service on vulnerab ...

Resolved issues

BugDescription
TEMP-0000000-F99584"slowloris" denial-of-service vulnerability in webservers
CVE-2024-23638Squid is a caching proxy for the Web. Due to an expired pointer refere ...
CVE-2023-50269Squid is a caching proxy for the Web. Due to an Uncontrolled Recursion ...
CVE-2023-49286Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and ...
CVE-2023-49285Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and ...
CVE-2023-46848Squid is vulnerable to Denial of Service, where a remote attacker can ...
CVE-2023-46847Squid is vulnerable to a Denial of Service, where a remote attacker c ...
CVE-2022-41318A buffer over-read was discovered in libntlmauth in Squid 2.5 through ...
CVE-2022-41317An issue was discovered in Squid 4.9 through 4.17 and 5.0.6 through 5. ...
CVE-2021-46784In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due ...
CVE-2021-33620Squid before 4.15 and 5.x before 5.0.6 allows remote servers to cause ...
CVE-2021-31808An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due ...
CVE-2021-31807An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. An ...
CVE-2021-31806An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due ...
CVE-2021-28652An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due ...
CVE-2021-28651An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due ...
CVE-2021-28116Squid through 4.14 and 5.x through 5.0.5, in some configurations, allo ...
CVE-2020-25097An issue was discovered in Squid through 4.13 and 5.x through 5.0.4. D ...
CVE-2020-24606Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perfor ...
CVE-2020-15811An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due ...
CVE-2020-15810An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due ...
CVE-2020-15049An issue was discovered in http/ContentLengthInterpreter.cc in Squid b ...
CVE-2020-14059An issue was discovered in Squid 5.x before 5.0.3. Due to an Incorrect ...
CVE-2020-11945An issue was discovered in Squid before 5.0.2. A remote attacker can r ...
CVE-2020-8450An issue was discovered in Squid before 4.10. Due to incorrect buffer ...
CVE-2020-8449An issue was discovered in Squid before 4.10. Due to incorrect input v ...
CVE-2019-18860Squid before 4.9, when certain web browsers are used, mishandles HTML ...
CVE-2019-18679An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to ...
CVE-2019-18678An issue was discovered in Squid 3.x and 4.x through 4.8. It allows at ...
CVE-2019-18677An issue was discovered in Squid 3.x and 4.x through 4.8 when the appe ...
CVE-2019-18676An issue was discovered in Squid 3.x and 4.x through 4.8. Due to incor ...
CVE-2019-13345The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_ ...
CVE-2019-12854Due to incorrect string termination, Squid cachemgr.cgi 4.0 through 4. ...
CVE-2019-12529An issue was discovered in Squid 2.x through 2.7.STABLE9, 3.x through ...
CVE-2019-12528An issue was discovered in Squid before 4.10. It allows a crafted FTP ...
CVE-2019-12527An issue was discovered in Squid 4.0.23 through 4.7. When checking Bas ...
CVE-2019-12526An issue was discovered in Squid before 4.9. URN response handling in ...
CVE-2019-12525An issue was discovered in Squid 3.3.9 through 3.5.28 and 4.x through ...
CVE-2019-12524An issue was discovered in Squid through 4.7. When handling requests f ...
CVE-2019-12523An issue was discovered in Squid before 4.9. When handling a URN reque ...
CVE-2019-12521An issue was discovered in Squid through 4.7. When Squid is parsing ES ...
CVE-2019-12520An issue was discovered in Squid through 4.7 and 5. When receiving a r ...
CVE-2019-12519An issue was discovered in Squid through 4.7. When handling the tag es ...
CVE-2019-3688The /usr/sbin/pinger binary packaged with squid in SUSE Linux Enterpri ...
CVE-2018-1000027The Squid Software Foundation Squid HTTP Caching Proxy version prior t ...
CVE-2018-1000024The Squid Software Foundation Squid HTTP Caching Proxy version 3.0 to ...
CVE-2018-19132Squid before 4.4, when SNMP is enabled, allows a denial of service (Me ...
CVE-2016-10003Incorrect HTTP Request header comparison in Squid HTTP Proxy 3.5.0.1 t ...
CVE-2016-10002Incorrect processing of responses to If-None-Modified HTTP conditional ...
CVE-2016-5408Stack-based buffer overflow in the munge_other_line function in cachem ...
CVE-2016-4556Double free vulnerability in Esi.cc in Squid 3.x before 3.5.18 and 4.x ...
CVE-2016-4555client_side_request.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.1 ...
CVE-2016-4554mime_header.cc in Squid before 3.5.18 allows remote attackers to bypas ...
CVE-2016-4553client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not p ...
CVE-2016-4054Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows ...
CVE-2016-4053Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote attackers to ...
CVE-2016-4052Multiple stack-based buffer overflows in Squid 3.x before 3.5.17 and 4 ...
CVE-2016-4051Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4 ...
CVE-2016-3948Squid 3.x before 3.5.16 and 4.x before 4.0.8 improperly perform bounds ...
CVE-2016-3947Heap-based buffer overflow in the Icmp6::Recv function in icmp/Icmp6.c ...
CVE-2016-2572http.cc in Squid 4.x before 4.0.7 relies on the HTTP status code after ...
CVE-2016-2571http.cc in Squid 3.x before 3.5.15 and 4.x before 4.0.7 proceeds with ...
CVE-2016-2570The Edge Side Includes (ESI) parser in Squid 3.x before 3.5.15 and 4.x ...
CVE-2016-2569Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not properly append ...
CVE-2016-2390The FwdState::connectedToPeer method in FwdState.cc in Squid before 3. ...
CVE-2015-5400Squid before 3.5.6 does not properly handle CONNECT method peer respon ...
CVE-2015-3455Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, a ...
CVE-2015-0881CRLF injection vulnerability in Squid before 3.1.1 allows remote attac ...
CVE-2014-9749Squid 3.4.4 through 3.4.11 and 3.5.0.1 through 3.5.1, when Digest auth ...
CVE-2014-7142The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain ...
CVE-2014-7141The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain ...
CVE-2014-6270Off-by-one error in the snmpHandleUdp function in snmp_core.cc in Squi ...
CVE-2014-3609HttpHdrRange.cc in Squid 3.x before 3.3.12 and 3.4.x before 3.4.6 allo ...
CVE-2014-0128Squid 3.1 before 3.3.12 and 3.4 before 3.4.4, when SSL-Bump is enabled ...
CVE-2013-4123client_side_request.cc in Squid 3.2.x before 3.2.13 and 3.3.x before 3 ...
CVE-2013-4115Buffer overflow in the idnsALookup function in dns_internal.cc in Squi ...
CVE-2013-1839The strHdrAcptLangGetItem function in errorpage.cc in Squid 3.2.x befo ...
CVE-2013-0189cachemgr.cgi in Squid 3.1.x and 3.2.x, possibly 3.1.22, 3.2.4, and oth ...
CVE-2012-5643Multiple memory leaks in tools/cachemgr.cc in cachemgr.cgi in Squid 2. ...
CVE-2011-4096The idnsGrokReply function in Squid before 3.1.16 does not properly fr ...
CVE-2011-3205Buffer overflow in the gopherToHTML function in gopher.cc in the Gophe ...
CVE-2010-3072The string-comparison functions in String.cci in Squid 3.x before 3.1. ...
CVE-2010-2951dns_internal.cc in Squid 3.1.6, when IPv6 DNS resolution is not enable ...
CVE-2010-0639The htcpHandleTstRequest function in htcp.c in Squid 2.x before 2.6.ST ...
CVE-2010-0308lib/rfc1035.c in Squid 2.x, 3.0 through 3.0.STABLE22, and 3.1 through ...
CVE-2009-2855The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allo ...
CVE-2009-2622Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 allows remote ...
CVE-2009-2621Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 does not prope ...
CVE-2009-0801Squid, when transparent interception mode is enabled, uses the HTTP Ho ...
CVE-2009-0478Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allo ...

Security announcements

DSA / DLADescription
ELA-1037-1squid3 - security update
ELA-743-1squid3 - security update
ELA-660-1squid3 - security update
DLA-2685-1squid3 - security update
ELA-442-1squid3 - security update
DLA-2598-1squid3 - security update
ELA-382-1squid3 - security update
ELA-294-1squid3 - security update
DLA-2394-1squid3 - security update
DLA-2278-3squid3 - regression update
ELA-271-1squid3 - security update
DLA-2278-2squid3 - regression update
DLA-2278-1squid3 - security update
DLA-2028-1squid3 - security update
DLA-1858-1squid3 - security update
DLA-1847-1squid3 - security update
DLA-1596-1squid3 - security update
DSA-4122-1squid3 - security update
DLA-1266-1squid3 - security update
DLA-763-1squid3 - security update
DSA-3745-1squid3 - security update
DSA-3625-1squid3 - security update
DLA-556-1squid3 - security update
DLA-478-1squid3 - security update
DSA-3522-1squid3 - security update
DLA-445-2squid3 - regression update
DLA-445-1squid3 - security update
DSA-3327-1squid3 - security update
DLA-286-1squid3 - security update
DLA-45-1squid3 - security update
DSA-3014-1squid3 - security update
DSA-2631-1squid3 - denial of service
DSA-2381-1squid3 - invalid memory deallocation
DSA-2304-1squid3 - buffer overflow
DSA-2111-1squid3 - denial of service
DSA-1991-1squid squid3 - denial of service
DSA-1843-2squid3 - regression fix
DSA-1843-1squid3 - denial of service
DSA-1732-1squid3 - denial of service

Search for package or bug name: Reporting problems