squid 4.10-1ubuntu1.8 source package in Ubuntu

Changelog

squid (4.10-1ubuntu1.8) focal-security; urgency=medium

  * SECURITY UPDATE: DoS via Gopher gateway
    - debian/patches/CVE-2023-46728.patch: disable gopher support in
      src/FwdState.cc, src/HttpRequest.cc, src/IoStats.h, src/Makefile.am,
      src/adaptation/ecap/Host.cc, src/adaptation/ecap/MessageRep.cc,
      src/anyp/ProtocolType.h, src/anyp/Uri.cc, src/anyp/UriScheme.cc,
      src/client_side_request.cc, src/err_type.h, src/HttpMsg.h,
      src/mgr/IoAction.cc, src/mgr/IoAction.h, src/stat.cc,
      src/Makefile.in.
    - CVE-2023-46728
  * SECURITY UPDATE: HTTP request smuggling, caused by chunked decoder
    lenience
    - debian/patches/CVE-2023-46846-pre1.patch: fix incremental parsing of
      chunked quoted extensions in src/adaptation/icap/ModXact.cc,
      src/adaptation/icap/ModXact.h, src/http/one/Parser.cc,
      src/http/one/Parser.h, src/http/one/RequestParser.cc,
      src/http/one/RequestParser.h, src/http/one/ResponseParser.cc,
      src/http/one/ResponseParser.h, src/http/one/TeChunkedParser.cc,
      src/http/one/TeChunkedParser.h, src/http/one/Tokenizer.cc,
      src/http/one/Tokenizer.h, src/http/one/forward.h,
      src/parser/BinaryTokenizer.h, src/parser/Makefile.am,
      src/parser/Tokenizer.cc, src/parser/Tokenizer.h,
      src/parser/forward.h.
    - debian/patches/CVE-2023-46846.patch: improve HTTP chunked encoding
      compliance in src/http/one/Parser.cc, src/http/one/Parser.h,
      src/http/one/TeChunkedParser.cc, src/parser/Tokenizer.cc,
      src/parser/Tokenizer.h.
    - CVE-2023-46846
  * SECURITY UPDATE: DoS via HTTP Digest Authentication
    - debian/patches/CVE-2023-46847.patch: fix stack buffer overflow when
      parsing Digest Authorization in src/auth/digest/Config.cc.
    - CVE-2023-46847

 -- Marc Deslauriers <email address hidden>  Mon, 13 Nov 2023 10:13:50 -0500

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Focal
Original maintainer:
Ubuntu Developers
Architectures:
any all
Section:
web
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
squid_4.10.orig.tar.xz 2.3 MiB 98f0100afd8a42ea5f6b81eb98b0e4b36d7a54beab1c73d2f1705ab49b025f1f
squid_4.10-1ubuntu1.8.debian.tar.xz 79.5 KiB 1d11714391b629c962625313bdd3a8bee8a9b10588c3811f0c1e50af42544b02
squid_4.10-1ubuntu1.8.dsc 2.7 KiB 0acd412f43df18aaa1fdc5fc4092b88832e036809e99be66e0ca25b6976ed704

View changes file

Binary packages built by this source

squid: Full featured Web Proxy cache (HTTP proxy)

 Squid is a high-performance proxy caching server for web clients, supporting
 FTP, gopher, ICY and HTTP data objects.

squid-cgi: Full featured Web Proxy cache (HTTP proxy) - control CGI

 Squid is a high-performance proxy caching server for web clients, supporting
 FTP, gopher, ICY and HTTP data objects.
 .
 This package contains a CGI program that can be used to query and administrate
 a `squid' proxy cache through a web browser.

squid-cgi-dbgsym: debug symbols for squid-cgi
squid-common: Full featured Web Proxy cache (HTTP proxy) - common files

 Squid is a high-performance proxy caching server for web clients, supporting
 FTP, gopher, ICY and HTTP data objects.
 .
 This package contains common files (MIB and icons)

squid-dbgsym: debug symbols for squid
squid-purge: Full featured Web Proxy cache (HTTP proxy) - cache management utility

 Squid is a high-performance proxy caching server for web clients, supporting
 FTP, gopher, ICY and HTTP data objects.
 .
 This package contains a small utility that can be used to manage the disk cache
 from the command line.

squid-purge-dbgsym: debug symbols for squid-purge
squidclient: Full featured Web Proxy cache (HTTP proxy) - HTTP(S) message utility

 Squid is a high-performance proxy caching server for web clients, supporting
 FTP, gopher, ICY and HTTP data objects.
 .
 This package contains a small utility that can be used to get URLs from the
 command line.

squidclient-dbgsym: debug symbols for squidclient