RHSA-2024:9644HighCVSS 7.5
Red Hat Security Advisory: squid:4 security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2024-23638 — squid: vulnerable to a Denial of Service attack against Cache Manager error responses CVE-2024-45802 — squid: Denial of Service processing ESI response content
🎯 Affected products31
- Red Hat Enterprise Linux AppStream (v. 8)
- libecap-0:1.0.1-2.module+el8.9.0+19703+a1da7223.aarch64 (squid:4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- libecap-0:1.0.1-2.module+el8.9.0+19703+a1da7223.ppc64le (squid:4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- libecap-0:1.0.1-2.module+el8.9.0+19703+a1da7223.s390x (squid:4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- libecap-0:1.0.1-2.module+el8.9.0+19703+a1da7223.src (squid:4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- libecap-0:1.0.1-2.module+el8.9.0+19703+a1da7223.x86_64 (squid:4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- libecap-debuginfo-0:1.0.1-2.module+el8.9.0+19703+a1da7223.aarch64 (squid:4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- libecap-debuginfo-0:1.0.1-2.module+el8.9.0+19703+a1da7223.ppc64le (squid:4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- libecap-debuginfo-0:1.0.1-2.module+el8.9.0+19703+a1da7223.s390x (squid:4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- libecap-debuginfo-0:1.0.1-2.module+el8.9.0+19703+a1da7223.x86_64 (squid:4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- libecap-debugsource-0:1.0.1-2.module+el8.9.0+19703+a1da7223.aarch64 (squid:4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- libecap-debugsource-0:1.0.1-2.module+el8.9.0+19703+a1da7223.ppc64le (squid:4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- libecap-debugsource-0:1.0.1-2.module+el8.9.0+19703+a1da7223.s390x (squid:4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- libecap-debugsource-0:1.0.1-2.module+el8.9.0+19703+a1da7223.x86_64 (squid:4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- libecap-devel-0:1.0.1-2.module+el8.9.0+19703+a1da7223.aarch64 (squid:4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- libecap-devel-0:1.0.1-2.module+el8.9.0+19703+a1da7223.ppc64le (squid:4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- libecap-devel-0:1.0.1-2.module+el8.9.0+19703+a1da7223.s390x (squid:4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- libecap-devel-0:1.0.1-2.module+el8.9.0+19703+a1da7223.x86_64 (squid:4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- squid-7:4.15-10.module+el8.10.0+22489+b920747d.3.aarch64 (squid:4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- squid-7:4.15-10.module+el8.10.0+22489+b920747d.3.ppc64le (squid:4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- squid-7:4.15-10.module+el8.10.0+22489+b920747d.3.s390x (squid:4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- squid-7:4.15-10.module+el8.10.0+22489+b920747d.3.src (squid:4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- squid-7:4.15-10.module+el8.10.0+22489+b920747d.3.x86_64 (squid:4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- squid-debuginfo-7:4.15-10.module+el8.10.0+22489+b920747d.3.aarch64 (squid:4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- squid-debuginfo-7:4.15-10.module+el8.10.0+22489+b920747d.3.ppc64le (squid:4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- squid-debuginfo-7:4.15-10.module+el8.10.0+22489+b920747d.3.s390x (squid:4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- squid-debuginfo-7:4.15-10.module+el8.10.0+22489+b920747d.3.x86_64 (squid:4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- squid-debugsource-7:4.15-10.module+el8.10.0+22489+b920747d.3.aarch64 (squid:4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- squid-debugsource-7:4.15-10.module+el8.10.0+22489+b920747d.3.ppc64le (squid:4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- squid-debugsource-7:4.15-10.module+el8.10.0+22489+b920747d.3.s390x (squid:4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- +1 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Restrict entry to Cache Manager through Squid's primary access control: http_access deny manager Workaround: This bug was mitigated by the default upstream build configuration of Squid since version 6.10.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2024:9644
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2260051
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2322154
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_9644.json