Bug 32501 - squid new security issues CVE-2023-4684[67]
Summary: squid new security issues CVE-2023-4684[67]
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: All Packagers
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on: 32486
Blocks:
  Show dependency treegraph
 
Reported: 2023-11-09 15:47 CET by Nicolas Salguero
Modified: 2024-01-08 09:58 CET (History)
3 users (show)

See Also:
Source RPM: squid-4.17-1.2.mga8.src.rpm
CVE:
Status comment:


Attachments

Description Nicolas Salguero 2023-11-09 15:47:36 CET
+++ This bug was initially created as a clone of Bug #32486 +++

Squid has issued advisories on October 21:
https://github.com/squid-cache/squid/security/advisories/GHSA-j83v-w3p4-5cqh
https://github.com/squid-cache/squid/security/advisories/GHSA-phqj-m8gv-cq4g
Nicolas Salguero 2023-11-09 15:48:05 CET

Source RPM: squid-5.9-1.mga9.src.rpm => squid-4.17-1.2.mga8.src.rpm

Comment 1 Lewis Smith 2023-11-09 20:43:30 CET
Nicolas has already corrected these CVEs in Cauldron fro Squid 5 (M9):
patches for CVE-2023-4684[6-8] (mga#32486)

These issues are not correctable for Squid 4 (M8). We might have to issue an advisory with the workarounds (or not) as below; + a hint to move to Mageia 9:

SQUID-2023:1 Request/Response smuggling in HTTP/1.1 and ICAP
Squid older than 5.1 have not been tested and should be
assumed to be vulnerable.
All Squid-5.x up to and including 5.9 are vulnerable.
All Squid-6.x up to and including 6.3 are vulnerable.

Workaround:

ICAP issues can be reduced by ensuring only trusted ICAP
services are used, with TLS encrypted connections
(ICAPS extension).

There is no workaround for the HTTP Request Smuggling issue.

SQUID-2023:3 Denial of Service in HTTP Digest Authentication
Squid older than 5.0.5 have not been tested and should be assumed
to be vulnerable.
All Squid-5.0.6 up to and including 5.9 are vulnerable.
All Squid-6.x up to and including 6.3 are vulnerable.

Workaround:

Disable HTTP Digest authentication until Squid can be
upgraded or patched.

Assigning this globally.

Assignee: bugsquad => pkg-bugs

Comment 2 Nicolas Salguero 2024-01-08 09:58:08 CET
Mageia 8 EOL

Status: NEW => RESOLVED
Resolution: (none) => OLD


Note You need to log in before you can comment on or make changes to this bug.