USN-6907-1: Squid vulnerability
23 July 2024
Squid could be made to crash if it processed specially crafted characters.
Releases
Packages
Details
Joshua Rogers discovered that Squid did not properly handle multi-byte
characters during Edge Side Includes (ESI) processing. A remote attacker
could possibly use this issue to cause a memory corruption error, leading
to a denial of service.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 24.04
Ubuntu 22.04
Ubuntu 20.04
Ubuntu 18.04
-
squid
-
3.5.27-1ubuntu1.14+esm3
Available with Ubuntu Pro
-
squid3
-
3.5.27-1ubuntu1.14+esm3
Available with Ubuntu Pro
Ubuntu 16.04
-
squid
-
3.5.12-1ubuntu7.16+esm4
Available with Ubuntu Pro
-
squid3
-
3.5.12-1ubuntu7.16+esm4
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.