Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 06 May 2016 16:18:20 +0000
From:      bugzilla-noreply@freebsd.org
To:        freebsd-ports-bugs@FreeBSD.org
Subject:   [Bug 209334] www/squid(-devel)?: update to latest version (multiple vulnerabilities)
Message-ID:  <bug-209334-13@https.bugs.freebsd.org/bugzilla/>

next in thread | raw e-mail | index | archive | help
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D209334

            Bug ID: 209334
           Summary: www/squid(-devel)?: update to latest version (multiple
                    vulnerabilities)
           Product: Ports & Packages
           Version: Latest
          Hardware: Any
                OS: Any
            Status: New
          Severity: Affects Only Me
          Priority: ---
         Component: Individual Port(s)
          Assignee: freebsd-ports-bugs@FreeBSD.org
          Reporter: timp87@gmail.com

Here is a list obtained here http://www.squid-cache.org/Advisories/:
  SQUID-2016:9, May 06, 2016
    Fixed from 4.0.10, 3.5.18=20
    Multiple Denial of Service issues in ESI Response processing.
  SQUID-2016:8, May 06, 2016
    Fixed from 4.0.10, 3.5.18=20
    Header smuggling issue in HTTP Request processing.
  SQUID-2016:7, May 06, 2016
    Fixed from 4.0.10, 3.5.18=20
    Cache poisoning issue in HTTP Request handling.


I'll provide patches a bit later.

--=20
You are receiving this mail because:
You are the assignee for the bug.=



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?bug-209334-13>