Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2023:7213 - Security Advisory
Issued:
2023-11-14
Updated:
2023-11-14

RHSA-2023:7213 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Critical: squid:4 security update

Type/Severity

Security Advisory: Critical

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for the squid:4 module is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Squid is a high-performance proxy caching server for web clients, supporting FTP, Gopher, and HTTP data objects.

Security Fix(es):

  • squid: Denial of Service in HTTP Digest Authentication (CVE-2023-46847)
  • squid: Request/Response smuggling in HTTP/1.1 and ICAP (CVE-2023-46846)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

After installing this update, the squid service will be restarted automatically.

Affected Products

  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for ARM 64 8 aarch64

Fixes

  • BZ - 2245910 - CVE-2023-46846 squid: Request/Response smuggling in HTTP/1.1 and ICAP
  • BZ - 2245916 - CVE-2023-46847 squid: Denial of Service in HTTP Digest Authentication

CVEs

  • CVE-2023-46846
  • CVE-2023-46847

References

  • https://access.redhat.com/security/updates/classification/#critical
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 8

SRPM
libecap-1.0.1-2.module+el8.9.0+19703+a1da7223.src.rpm SHA-256: 68456b844f86281a4db4053345c0704bea4293018ca2cd394f979ba8cd263cb4
squid-4.15-7.module+el8.9.0+20571+8d39338b.1.src.rpm SHA-256: 247270663b5838ddcb7ac7219173044136d53a41b17a37f64502d5ba7a3a7a3d
x86_64
libecap-1.0.1-2.module+el8.9.0+19703+a1da7223.x86_64.rpm SHA-256: 40d43cf013f21f97631fb8470285164a523071f7882f748663494c0f1625b427
libecap-debuginfo-1.0.1-2.module+el8.9.0+19703+a1da7223.x86_64.rpm SHA-256: 6e683c898b1c714b9485a0acb012d0e5b71ddb75514cf6a37ee472ad6c373bd9
libecap-debugsource-1.0.1-2.module+el8.9.0+19703+a1da7223.x86_64.rpm SHA-256: f9d480af68e77827a9e84e1cdc2b9d48fefda63dceec87b54114568520ba6ca7
libecap-devel-1.0.1-2.module+el8.9.0+19703+a1da7223.x86_64.rpm SHA-256: 11b5623fb94967adf20000120212bb87d5e0485c1a4d17ccaeea54bf45abeaca
squid-4.15-7.module+el8.9.0+20571+8d39338b.1.x86_64.rpm SHA-256: 87b9dbf78d82305b8012c7993d1df86e155c9bf38259d3b5521b27de743686b4
squid-debuginfo-4.15-7.module+el8.9.0+20571+8d39338b.1.x86_64.rpm SHA-256: 16fb797024c55439618469e1c883e1bf4ae27bc3e5f2ad1b33bc8f114ce7b11e
squid-debugsource-4.15-7.module+el8.9.0+20571+8d39338b.1.x86_64.rpm SHA-256: 5c77dab08ff150018602ada5e05056f45ee4ba156a1be515aaa2df248a07e32d

Red Hat Enterprise Linux for IBM z Systems 8

SRPM
libecap-1.0.1-2.module+el8.9.0+19703+a1da7223.src.rpm SHA-256: 68456b844f86281a4db4053345c0704bea4293018ca2cd394f979ba8cd263cb4
squid-4.15-7.module+el8.9.0+20571+8d39338b.1.src.rpm SHA-256: 247270663b5838ddcb7ac7219173044136d53a41b17a37f64502d5ba7a3a7a3d
s390x
libecap-1.0.1-2.module+el8.9.0+19703+a1da7223.s390x.rpm SHA-256: 7b177d330230a2a8637f1f46c83e52796fc981f307861cd5ac4e4ff46759a6a3
libecap-debuginfo-1.0.1-2.module+el8.9.0+19703+a1da7223.s390x.rpm SHA-256: cdaadf99ef98a02d12f5047e680e5f40c71f7a2df68e2808343242f0a37bf76d
libecap-debugsource-1.0.1-2.module+el8.9.0+19703+a1da7223.s390x.rpm SHA-256: 24efacc784d597f773c9856ed0ed99d78f9c0b9ece1b84de60cef147298e9c01
libecap-devel-1.0.1-2.module+el8.9.0+19703+a1da7223.s390x.rpm SHA-256: e7d1d34aaeb21d0dbcb11af624315ecd47b7d7b644edd52ea09f0f0614bb6f54
squid-4.15-7.module+el8.9.0+20571+8d39338b.1.s390x.rpm SHA-256: 057e74f53616bf96ca2ac4f14e3dc2b20fb84e0062de111f75648934c1f6b0ba
squid-debuginfo-4.15-7.module+el8.9.0+20571+8d39338b.1.s390x.rpm SHA-256: b8162ca0bdf5b8ed7ca5ef5eecb366c57323648d0b8c459fa945ffe64ab06c60
squid-debugsource-4.15-7.module+el8.9.0+20571+8d39338b.1.s390x.rpm SHA-256: 623755893c6024ccd6c2a24e181f3ea6474787144f27e57f5aa3eb2537b0c21d

Red Hat Enterprise Linux for Power, little endian 8

SRPM
libecap-1.0.1-2.module+el8.9.0+19703+a1da7223.src.rpm SHA-256: 68456b844f86281a4db4053345c0704bea4293018ca2cd394f979ba8cd263cb4
squid-4.15-7.module+el8.9.0+20571+8d39338b.1.src.rpm SHA-256: 247270663b5838ddcb7ac7219173044136d53a41b17a37f64502d5ba7a3a7a3d
ppc64le
libecap-1.0.1-2.module+el8.9.0+19703+a1da7223.ppc64le.rpm SHA-256: 779f161dd569dae1700e0acfd9169bd55763db01ad3112207fbcd49716bfd58f
libecap-debuginfo-1.0.1-2.module+el8.9.0+19703+a1da7223.ppc64le.rpm SHA-256: 6720c36ff829fc1b8004458fb08001f1fd8b3a40bdd57e418543a3b890421129
libecap-debugsource-1.0.1-2.module+el8.9.0+19703+a1da7223.ppc64le.rpm SHA-256: 8120cedcc13b839d73ed203a89ebbfe1803579e0549be7ae5adab0976f1fe0de
libecap-devel-1.0.1-2.module+el8.9.0+19703+a1da7223.ppc64le.rpm SHA-256: fe6d7e62eb8f5eb30ccd717c5c46cc9c1f6388b158515d25149d259bf30e7737
squid-4.15-7.module+el8.9.0+20571+8d39338b.1.ppc64le.rpm SHA-256: c9c38dc472901d98b4d84b4b8ec6a19e59b7fdf391158b634b2269b6652ba262
squid-debuginfo-4.15-7.module+el8.9.0+20571+8d39338b.1.ppc64le.rpm SHA-256: 429a17fc916dfb05d28a26f1ce26cc341ae16dba5ff3f67c090b62a4ecccdbbc
squid-debugsource-4.15-7.module+el8.9.0+20571+8d39338b.1.ppc64le.rpm SHA-256: ec92fb6d93cbff12b1dbe34fa61a58e4555c6256128dea24dde91c49bb42c25e

Red Hat Enterprise Linux for ARM 64 8

SRPM
libecap-1.0.1-2.module+el8.9.0+19703+a1da7223.src.rpm SHA-256: 68456b844f86281a4db4053345c0704bea4293018ca2cd394f979ba8cd263cb4
squid-4.15-7.module+el8.9.0+20571+8d39338b.1.src.rpm SHA-256: 247270663b5838ddcb7ac7219173044136d53a41b17a37f64502d5ba7a3a7a3d
aarch64
libecap-1.0.1-2.module+el8.9.0+19703+a1da7223.aarch64.rpm SHA-256: 32b30079509b8d16ed9e85fb0ed15c0e2a8efae115f9fd5622219b65d2363db8
libecap-debuginfo-1.0.1-2.module+el8.9.0+19703+a1da7223.aarch64.rpm SHA-256: 72b65db7b4a0220a8185e142c1fc8e2c56480b05028a924138ea24d1ce90b3dd
libecap-debugsource-1.0.1-2.module+el8.9.0+19703+a1da7223.aarch64.rpm SHA-256: d408408456d44c98da25fb4dc3dbd7de545b3ffa6de8527bd7598a366a7012a3
libecap-devel-1.0.1-2.module+el8.9.0+19703+a1da7223.aarch64.rpm SHA-256: 0b78af9f6df4a8580f41145718d3f5b0d52bf566bdc6fed26b2ed8c8140f42bc
squid-4.15-7.module+el8.9.0+20571+8d39338b.1.aarch64.rpm SHA-256: 4236a57f1814057990f7107df2bd5fcc13c679258d69a30e5b100d8e7bb86160
squid-debuginfo-4.15-7.module+el8.9.0+20571+8d39338b.1.aarch64.rpm SHA-256: d37d43463d264c11505063330fac5635b33e14006fde111d5bd49d99028f59c4
squid-debugsource-4.15-7.module+el8.9.0+20571+8d39338b.1.aarch64.rpm SHA-256: 522addbe98b0c9fb86e89be865f1209df9391d7bc3675d497e622fdaf00a7b8c

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat, Inc.

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility