On 2020/04/23 04:54, Stuart Henderson wrote: > CVSROOT: /cvs > Module name: ports > Changes by: [email protected] 2020/04/23 04:54:48 > > Modified files: > www/squid : Makefile distinfo > > Log message: > update to squid-4.11 > > SQUID-2020:3 - Due to incorrect buffer handling Squid is vulnerable to > cache poisoning, remote execution, and denial of service attacks when > processing ESI responses.
oops, this one was actually SQUID-2019:12 > SQUID-2020:4 - Due to an integer overflow bug Squid is vulnerable to > credential replay and remote code execution attacks against HTTP Digest > Authentication tokens. >
