ALSA-2024:0071
Dashboard / Vulnerabilities / ALSA-2024:0071
ALSA-2024:0071
Summary: Important: squid security update
Details: Squid is a high-performance proxy caching server for web clients, supporting FTP, Gopher, and HTTP data objects. Security Fix(es): * squid: Denial of Service in SSL Certificate validation (CVE-2023-46724) * squid: NULL pointer dereference in the gopher protocol code (CVE-2023-46728) * squid: Buffer over-read in the HTTP Message processing feature (CVE-2023-49285) * squid: Incorrect Check of Function Return Value In Helper Process management (CVE-2023-49286) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
References: https://access.redhat.com/errata/RHSA-2024:0071, https://access.redhat.com/security/cve/CVE-2023-46724, https://access.redhat.com/security/cve/CVE-2023-46728, https://access.redhat.com/security/cve/CVE-2023-49285, https://access.redhat.com/security/cve/CVE-2023-49286, https://bugzilla.redhat.com/2247567, https://bugzilla.redhat.com/2248521, https://bugzilla.redhat.com/2252923, https://bugzilla.redhat.com/2252926, https://errata.almalinux.org/9/ALSA-2024-0071.html
Affected packages
Package
Name: squid
Purl: pkg:rpm/almalinux/squid
Affected ranges
Type: ECOSYSTEM
Events:
