This bug was fixed in the package squid - 6.9-1ubuntu1 --------------- squid (6.9-1ubuntu1) oracular; urgency=medium
* Merge with Debian unstable (LP: #2064466). Remaining changes: - d/usr.sbin.squid: Add sections for squid-deb-proxy and squidguard - d/p/90-cf.data.ubuntu.patch: Add refresh patterns for deb packaging - Use snakeoil certificates: + d/control: add ssl-cert to dependencies + d/p/99-ubuntu-ssl-cert-snakeoil.patch: add a note about ssl to the default config file - d/NEWS: drop the NIS basic auth helper (LP #1895694) - d/p/0009-Fix-Werror-alloc-size-larger-than-on-GCC-12.patch: Fix FTBFS due to -Werror=alloc-size-larger-than on GCC 12. - d/rules: halt build upon test failures. - d/rules: do not include additional configuration files during build time tests. This would lead to test failures due to missing paths. - d/t/upstream-test-suite: use installed squid binary for autopkgtest config file checks. - d/p/0010-Fix-Werror-sign-compare-on-GCC-13.patch: fix comparison between signed and unsigned values. - d/rules: disable LTO related compilation errors for ppc64el builds. - d/source_squid.py, d/squid-common.install: Add apport hook (LP #676141) * Dropped changes: - SECURITY UPDATE: DoS via chunked decoder uncontrolled recursion bug + debian/patches/CVE-2024-25111.patch: fix infinite recursion in src/http.cc, src/http.h. + CVE-2024-25111 [ Fixed in 6.8 ] * New changes: - d/t/upstream-test-suite: adjust autopkgtests following dpkg changes enabling ELF metadata. (LP: #2071468) squid (6.9-1) unstable; urgency=medium [ Amos Jeffries <amosjeffr...@squid-cache.org> ] * New Upstream Release 6.9 squid (6.8-1) unstable; urgency=high [ Amos Jeffries <amosjeffr...@squid-cache.org> ] * New Upstream Release 6.8 Fixes: CVE-2024-25111. SQUID-2024:1 [ Luigi Gangitano <lu...@debian.org> ] * debian/control - Migrate from pkg-config to pkgconf -- Athos Ribeiro <athos.ribe...@canonical.com> Tue, 02 Jul 2024 14:21:39 -0300 ** Changed in: squid (Ubuntu) Status: Triaged => Fix Released ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2024-25111 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2071468 Title: ELF package metadata failure: environment variable ‘DEB_HOST_ARCH’ not defined To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/asymptote/+bug/2071468/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs