|
|
Log in / Subscribe / Register

Ubuntu alert USN-7845-1 (squid, squid3)

From:  noreply+usn-bot@canonical.com
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-7845-1] Squid vulnerability
Date:  Tue, 28 Oct 2025 23:43:26 +0000
Message-ID:  <E1vDtLa-0002qx-Mg@lists.ubuntu.com>

========================================================================== Ubuntu Security Notice USN-7845-1 October 28, 2025 squid, squid3 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 25.04 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Squid would allow unintended access to sensitive information over the network. Software Description: - squid: Web proxy cache server - squid3: Web proxy cache server Details: Leonardo Giovannini discovered that Squid failed to redact HTTP Authentication credentials in a default configuration. An attacker could possibly use this issue to obtain sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 squid 6.13-1ubuntu4.1 Ubuntu 25.04 squid 6.13-1ubuntu1.2 Ubuntu 24.04 LTS squid 6.13-0ubuntu0.24.04.3 Ubuntu 22.04 LTS squid 5.9-0ubuntu0.22.04.4 Ubuntu 20.04 LTS squid 4.10-1ubuntu1.13+esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS squid 3.5.27-1ubuntu1.14+esm4 Available with Ubuntu Pro squid3 3.5.27-1ubuntu1.14+esm4 Available with Ubuntu Pro Ubuntu 16.04 LTS squid 3.5.12-1ubuntu7.16+esm5 Available with Ubuntu Pro squid3 3.5.12-1ubuntu7.16+esm5 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7845-1 CVE-2025-62168 Package Information: https://launchpad.net/ubuntu/+source/squid/6.13-1ubuntu4.1 https://launchpad.net/ubuntu/+source/squid/6.13-1ubuntu1.2 https://launchpad.net/ubuntu/+source/squid/6.13-0ubuntu0.... https://launchpad.net/ubuntu/+source/squid/5.9-0ubuntu0.2...


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmkBVFIACgkQcpJm3tlz hgEjfg/+PazBl1u3ZBJ+tvt+B9X/uY7O8rNACAUuGBe/4zPfdnBtWxZMGaMfoj3J 9tKeJxnWbSbWVs7U0IQjwfsja6ApqJ5YWRoN3BW+WpAa/OOuoPKjbbyTn+qq9c1O nbAkPP2P6leQ6W4DBLomNfA7POKXBS/BD7Da+UUJusXV1zieMbTF3cXhh0d/UXtq FZghrqH9Gc2dslvg9FBw2Pichmjopy4RiqVqvDQP6Kjx/+8VUUeYf+TjEFepKTSk SJaKIL8iusPth0bt3+RwE/Sg2H6C55RmE6UY9CubYhPcOiyff89GJog0nwO5SRge U0ImvwX8eLq3vzP25yK6AeVsSh4wSW+GC+q7kIatBjmqxXmkHsPyB5fbTz+s3FGM QXLtCPBlfH20CYxBuwQca8tYhrIurukSecGOC0DnNAaHZfzC5VJRaB4ieON5ci+y 3t3hlNgKLFniiwGxHfYgMb+MI6kzT3y2xc1bA36XtXVwhVIrDPk49+Rib/VYpJaQ B/OTDwhU3Kbv3iViQPk/Yr3goQY5fUCtZ+YTGc816M9xO1z55NnbwKjbmujhJWbv 9v4EfyQjOXLE098/tuWOKMFi5xXo8atqIYoWySj4DDMfWPh6QywLQ0Y0PpFnRqej /OxUlles2jhD3GBTNEAUTikUq4j98KBtJx8xBtKsWsKODJ8lffA= =DEVS -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds