Information on source package squid

Available versions

ReleaseVersion
buster4.4-1
sid4.4-1

Open unimportant issues

BugbustersidDescription
CVE-2018-1172vulnerablevulnerableThis vulnerability allows remote attackers to deny service on ...
CVE-2016-2390vulnerablevulnerableThe FwdState::connectedToPeer method in FwdState.cc in Squid before ...
CVE-2015-3455vulnerablevulnerableSquid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, ...
CVE-2014-6270vulnerablevulnerableOff-by-one error in the snmpHandleUdp function in snmp_core.cc in ...
CVE-2009-0801vulnerablevulnerableSquid, when transparent interception mode is enabled, uses the HTTP ...

Resolved issues

BugDescription
TEMP-0000000-589A35"slowloris" denial-of-service vulnerabilty in webservers
CVE-2018-19132Squid before 4.4, when SNMP is enabled, allows a denial of service ...
CVE-2018-19131Squid before 4.4 has XSS via a crafted X.509 certificate during HTTP(S) ...
CVE-2018-1000027The Squid Software Foundation Squid HTTP Caching Proxy version prior ...
CVE-2018-1000024The Squid Software Foundation Squid HTTP Caching Proxy version 3.0 to ...
CVE-2016-4556Double free vulnerability in Esi.cc in Squid 3.x before 3.5.18 and 4.x ...
CVE-2016-4555client_side_request.cc in Squid 3.x before 3.5.18 and 4.x before ...
CVE-2016-4554mime_header.cc in Squid before 3.5.18 allows remote attackers to ...
CVE-2016-4553client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not ...
CVE-2016-4054Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows ...
CVE-2016-4053Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote attackers to ...
CVE-2016-4052Multiple stack-based buffer overflows in Squid 3.x before 3.5.17 and ...
CVE-2016-4051Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and ...
CVE-2016-3948Squid 3.x before 3.5.16 and 4.x before 4.0.8 improperly perform bounds ...
CVE-2016-3947Heap-based buffer overflow in the Icmp6::Recv function in ...
CVE-2016-2572http.cc in Squid 4.x before 4.0.7 relies on the HTTP status code after ...
CVE-2016-2571http.cc in Squid 3.x before 3.5.15 and 4.x before 4.0.7 proceeds with ...
CVE-2016-2570The Edge Side Includes (ESI) parser in Squid 3.x before 3.5.15 and 4.x ...
CVE-2016-2569Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not properly append ...
CVE-2015-5400Squid before 3.5.6 does not properly handle CONNECT method peer ...
CVE-2015-0881CRLF injection vulnerability in Squid before 3.1.1 allows remote ...
CVE-2014-9749Squid 3.4.4 through 3.4.11 and 3.5.0.1 through 3.5.1, when Digest ...
CVE-2014-7142The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain ...
CVE-2014-7141The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain ...
CVE-2014-3609HttpHdrRange.cc in Squid 3.x before 3.3.12 and 3.4.x before 3.4.6 ...
CVE-2014-0128Squid 3.1 before 3.3.12 and 3.4 before 3.4.4, when SSL-Bump is ...
CVE-2013-4123client_side_request.cc in Squid 3.2.x before 3.2.13 and 3.3.x before ...
CVE-2013-4115Buffer overflow in the idnsALookup function in dns_internal.cc in ...
CVE-2013-0189cachemgr.cgi in Squid 3.1.x and 3.2.x, possibly 3.1.22, 3.2.4, and ...
CVE-2012-5643Multiple memory leaks in tools/cachemgr.cc in cachemgr.cgi in Squid ...
CVE-2011-3205Buffer overflow in the gopherToHTML function in gopher.cc in the ...
CVE-2010-3072The string-comparison functions in String.cci in Squid 3.x before ...
CVE-2010-0639The htcpHandleTstRequest function in htcp.c in Squid 2.x before ...
CVE-2010-0308lib/rfc1035.c in Squid 2.x, 3.0 through 3.0.STABLE22, and 3.1 through ...
CVE-2009-2855The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 ...
CVE-2009-2622Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 allows remote ...
CVE-2009-2621Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 does not ...
CVE-2009-0478Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 ...
CVE-2008-1612The arrayShrink function (lib/Array.c) in Squid 2.6.STABLE17 allows ...
CVE-2007-6239The "cache update reply processing" functionality in Squid 2.x before ...
CVE-2007-1560The clientProcessRequest() function in src/client_side.c in Squid 2.6 ...
CVE-2007-0248The aclMatchExternal function in Squid before 2.6.STABLE7 allows ...
CVE-2007-0247squid/src/ftp.c in Squid before 2.6.STABLE7 allows remote FTP servers ...
CVE-2005-3322Unspecified vulnerability in Squid on SUSE Linux 9.0 allows remote ...
CVE-2005-3258The rfc1738_do_escape function in ftp.c for Squid 2.5 STABLE11 and ...
CVE-2005-2917Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, ...
CVE-2005-2796The sslConnectTimeout function in ssl.c for Squid 2.5.STABLE10 and ...
CVE-2005-2794store.c in Squid 2.5.STABLE10 and earlier allows remote attackers to ...
CVE-2005-1519Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered ...
CVE-2005-1345Squid 2.5.STABLE9 and earlier does not trigger a fatal error when it ...
CVE-2005-0718Squid 2.5.STABLE7 and earlier allows remote attackers to cause a ...
CVE-2005-0626Race condition in Squid 2.5.STABLE7 to 2.5.STABLE9, when using the ...
CVE-2005-0446Squid 2.5.STABLE8 and earlier allows remote attackers to cause a ...
CVE-2005-0241The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 ...
CVE-2005-0211Buffer overflow in wccp.c in Squid 2.5 before 2.5.STABLE7 allows ...
CVE-2005-0194Squid 2.5, when processing the configuration file, parses empty Access ...
CVE-2005-0175Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the ...
CVE-2005-0174Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the ...
CVE-2005-0173squid_ldap_auth in Squid 2.5 and earlier allows remote authenticated ...
CVE-2005-0097The NTLM component in Squid 2.5.STABLE7 and earlier allows remote ...
CVE-2005-0096Memory leak in the NTLM fakeauth_auth helper for Squid 2.5.STABLE7 and ...
CVE-2005-0095The WCCP message parsing code in Squid 2.5.STABLE7 and earlier allows ...
CVE-2005-0094Buffer overflow in the gopherToHTML function in the Gopher reply ...
CVE-2004-2654The clientAbortBody function in client_side.c in Squid Web Proxy Cache ...
CVE-2004-2480Squid Web Proxy Cache 2.3.STABLE5 allows remote attackers to bypass ...
CVE-2004-2479Squid Web Proxy Cache 2.5 might allow remote attackers to obtain ...
CVE-2004-0918The asn_parse_header function (asn1.c) in the SNMP module for Squid ...
CVE-2004-0832The (1) ntlm_fetch_string and (2) ntlm_get_string functions in Squid ...
CVE-2004-0541Buffer overflow in the ntlm_check_auth (NTLM authentication) function ...
CVE-2004-0189The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows ...
CVE-2002-0916Format string vulnerability in the allowuser code for the Stellar-X ...
CVE-2002-0735Format string vulnerability in the logging() function in C-Note Squid ...
CVE-2002-0715Vulnerability in Squid before 2.4.STABLE6 related to proxy ...
CVE-2002-0714FTP proxy in Squid before 2.4.STABLE6 does not compare the IP ...
CVE-2002-0713Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to ...
CVE-1999-0710The Squid package in Red Hat Linux 5.2 and 6.0, and other ...

Security announcements

DSA / DLADescription
DLA-1267-1squid - security update
DLA-558-1squid - security update
DLA-216-1squid - security update
DSA-3139-1squid - security update
DSA-1991-1squid squid3 - denial of service
DSA-1991-1squid squid3 - denial of service
DSA-1843-1squid3 - denial of service
DSA-1646-2squid - array bounds check
DSA-1482-1squid - programming error
DSA-809-3squid - assertion error
DSA-809-3squid - assertion error
DSA-828-1squid - several
DSA-828-1squid - several
DSA-809-1squid - several
DSA-751-1squid - IP spoofing
DSA-721-1squid - design flaw
DSA-688-1squid - mising input sanitising
DSA-667-1squid - several
DSA-651-1squid - buffer overflow, integer overflow
DSA-576-1squid - multiple
DSA-474squid - ACL bypass

Search for package or bug name: Reporting problems