Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:1787 - Security Advisory
Issued:
2024-04-11
Updated:
2024-04-11

RHSA-2024:1787 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: squid security update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for squid is now available for Red Hat Enterprise Linux 7.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Squid is a high-performance proxy caching server for web clients, supporting FTP, Gopher, and HTTP data objects.

Security Fix(es):

  • squid: denial of service in HTTP header parser (CVE-2024-25617)
  • squid: denial of service in HTTP request parsing (CVE-2023-50269)
  • squid: Buffer over-read in the HTTP Message processing feature (CVE-2023-49285)
  • squid: Incorrect Check of Function Return Value In Helper Process management (CVE-2023-49286)
  • squid: NULL pointer dereference in the gopher protocol code (CVE-2023-46728)
  • squid: Denial of Service in SSL Certificate validation (CVE-2023-46724)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

After installing this update, the squid service will be restarted automatically.

Affected Products

  • Red Hat Enterprise Linux Server 7 x86_64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64
  • Red Hat Enterprise Linux Workstation 7 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 7 s390x
  • Red Hat Enterprise Linux for Power, big endian 7 ppc64
  • Red Hat Enterprise Linux for Power, little endian 7 ppc64le
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 s390x
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 ppc64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 ppc64le

Fixes

  • BZ - 2247567 - CVE-2023-46724 squid: Denial of Service in SSL Certificate validation
  • BZ - 2248521 - CVE-2023-46728 squid: NULL pointer dereference in the gopher protocol code
  • BZ - 2252923 - CVE-2023-49286 squid: Incorrect Check of Function Return Value In Helper Process management
  • BZ - 2252926 - CVE-2023-49285 squid: Buffer over-read in the HTTP Message processing feature
  • BZ - 2254663 - CVE-2023-50269 squid: denial of service in HTTP request parsing
  • BZ - 2264309 - CVE-2024-25617 squid: denial of service in HTTP header parser

CVEs

  • CVE-2023-46724
  • CVE-2023-46728
  • CVE-2023-49285
  • CVE-2023-49286
  • CVE-2023-50269
  • CVE-2024-25617

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server 7

SRPM
squid-3.5.20-17.el7_9.10.src.rpm SHA-256: 6caadc8b302f34069bcc58566b1b940d4f15f060a32081ad6532d01d63299572
x86_64
squid-3.5.20-17.el7_9.10.x86_64.rpm SHA-256: 319d4abb9f244153cbe27b9a93e1d153af75cb087626d418e04d248851f945ef
squid-debuginfo-3.5.20-17.el7_9.10.x86_64.rpm SHA-256: bac84922cb1135f8f8552602eb3a495c36d7368e0468fd577d5d9f9e38696900
squid-debuginfo-3.5.20-17.el7_9.10.x86_64.rpm SHA-256: bac84922cb1135f8f8552602eb3a495c36d7368e0468fd577d5d9f9e38696900
squid-migration-script-3.5.20-17.el7_9.10.x86_64.rpm SHA-256: 3f3251c39cb7658855071c551528422c3b7e0b7efbd93e42526dc6ee958feccc
squid-sysvinit-3.5.20-17.el7_9.10.x86_64.rpm SHA-256: 2c9f9282d8e5f182d78bfe1ac65e392df291d5490562bbb42c7727021d3da0cb

Red Hat Enterprise Linux Server - Extended Life Cycle Support 7

SRPM
squid-3.5.20-17.el7_9.10.src.rpm SHA-256: 6caadc8b302f34069bcc58566b1b940d4f15f060a32081ad6532d01d63299572
x86_64
squid-3.5.20-17.el7_9.10.x86_64.rpm SHA-256: 319d4abb9f244153cbe27b9a93e1d153af75cb087626d418e04d248851f945ef
squid-debuginfo-3.5.20-17.el7_9.10.x86_64.rpm SHA-256: bac84922cb1135f8f8552602eb3a495c36d7368e0468fd577d5d9f9e38696900
squid-debuginfo-3.5.20-17.el7_9.10.x86_64.rpm SHA-256: bac84922cb1135f8f8552602eb3a495c36d7368e0468fd577d5d9f9e38696900
squid-migration-script-3.5.20-17.el7_9.10.x86_64.rpm SHA-256: 3f3251c39cb7658855071c551528422c3b7e0b7efbd93e42526dc6ee958feccc
squid-sysvinit-3.5.20-17.el7_9.10.x86_64.rpm SHA-256: 2c9f9282d8e5f182d78bfe1ac65e392df291d5490562bbb42c7727021d3da0cb

Red Hat Enterprise Linux Workstation 7

SRPM
squid-3.5.20-17.el7_9.10.src.rpm SHA-256: 6caadc8b302f34069bcc58566b1b940d4f15f060a32081ad6532d01d63299572
x86_64
squid-3.5.20-17.el7_9.10.x86_64.rpm SHA-256: 319d4abb9f244153cbe27b9a93e1d153af75cb087626d418e04d248851f945ef
squid-debuginfo-3.5.20-17.el7_9.10.x86_64.rpm SHA-256: bac84922cb1135f8f8552602eb3a495c36d7368e0468fd577d5d9f9e38696900
squid-debuginfo-3.5.20-17.el7_9.10.x86_64.rpm SHA-256: bac84922cb1135f8f8552602eb3a495c36d7368e0468fd577d5d9f9e38696900
squid-migration-script-3.5.20-17.el7_9.10.x86_64.rpm SHA-256: 3f3251c39cb7658855071c551528422c3b7e0b7efbd93e42526dc6ee958feccc
squid-sysvinit-3.5.20-17.el7_9.10.x86_64.rpm SHA-256: 2c9f9282d8e5f182d78bfe1ac65e392df291d5490562bbb42c7727021d3da0cb

Red Hat Enterprise Linux for IBM z Systems 7

SRPM
squid-3.5.20-17.el7_9.10.src.rpm SHA-256: 6caadc8b302f34069bcc58566b1b940d4f15f060a32081ad6532d01d63299572
s390x
squid-3.5.20-17.el7_9.10.s390x.rpm SHA-256: c9356091072001ba968f0eae233847a2c6aefd9547a146f4b1d8caa792ac6913
squid-debuginfo-3.5.20-17.el7_9.10.s390x.rpm SHA-256: 6d244f1945ede1accab10eea28cb81651ebc9fce31f4774145e495297329fb5b
squid-debuginfo-3.5.20-17.el7_9.10.s390x.rpm SHA-256: 6d244f1945ede1accab10eea28cb81651ebc9fce31f4774145e495297329fb5b
squid-migration-script-3.5.20-17.el7_9.10.s390x.rpm SHA-256: 84da9ccc5f308c5a6e42c7dc2d3096983479003d971637114b05f42dc1dd6280
squid-sysvinit-3.5.20-17.el7_9.10.s390x.rpm SHA-256: 5cb346bc8cf1a52a7e0d26eab0135b1a4bad4f0271317acb44f1ba07e38c4491

Red Hat Enterprise Linux for Power, big endian 7

SRPM
squid-3.5.20-17.el7_9.10.src.rpm SHA-256: 6caadc8b302f34069bcc58566b1b940d4f15f060a32081ad6532d01d63299572
ppc64
squid-3.5.20-17.el7_9.10.ppc64.rpm SHA-256: 8426aae429d4b166975c384e230264e967bd777c95a0cb32ac86c3a875ff6699
squid-debuginfo-3.5.20-17.el7_9.10.ppc64.rpm SHA-256: 6fbf55e7f35a21b36ebfa0b2ea511c346c6b4d6549c7f436e1d60bd1dc7a1b6c
squid-debuginfo-3.5.20-17.el7_9.10.ppc64.rpm SHA-256: 6fbf55e7f35a21b36ebfa0b2ea511c346c6b4d6549c7f436e1d60bd1dc7a1b6c
squid-migration-script-3.5.20-17.el7_9.10.ppc64.rpm SHA-256: 334fb3d5580f23738486837ed6724059cecda668e3564cd7efd373874ede90fa
squid-sysvinit-3.5.20-17.el7_9.10.ppc64.rpm SHA-256: 14b24c7a6419aed4bd12b5e7e9a39469fa25fb68dccad346ec70172d1077f5f3

Red Hat Enterprise Linux for Power, little endian 7

SRPM
squid-3.5.20-17.el7_9.10.src.rpm SHA-256: 6caadc8b302f34069bcc58566b1b940d4f15f060a32081ad6532d01d63299572
ppc64le
squid-3.5.20-17.el7_9.10.ppc64le.rpm SHA-256: 3be561764ae4bfd1a70343551b157ebff957255fb834c7c7c3d369252c109954
squid-debuginfo-3.5.20-17.el7_9.10.ppc64le.rpm SHA-256: 6636e541de272cc63d14907075854ce133575b8617c3dc822716c18d10c4fc33
squid-debuginfo-3.5.20-17.el7_9.10.ppc64le.rpm SHA-256: 6636e541de272cc63d14907075854ce133575b8617c3dc822716c18d10c4fc33
squid-migration-script-3.5.20-17.el7_9.10.ppc64le.rpm SHA-256: 970e28d760419a39b2e72587ea2f3089e7f4bf34b0427766a4d8fe61b636b665
squid-sysvinit-3.5.20-17.el7_9.10.ppc64le.rpm SHA-256: fe71e081d21b9b9a6f00a43f2e9605b5fc0285e35cddf9837e254450b86ddaa3

Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7

SRPM
squid-3.5.20-17.el7_9.10.src.rpm SHA-256: 6caadc8b302f34069bcc58566b1b940d4f15f060a32081ad6532d01d63299572
s390x
squid-3.5.20-17.el7_9.10.s390x.rpm SHA-256: c9356091072001ba968f0eae233847a2c6aefd9547a146f4b1d8caa792ac6913
squid-debuginfo-3.5.20-17.el7_9.10.s390x.rpm SHA-256: 6d244f1945ede1accab10eea28cb81651ebc9fce31f4774145e495297329fb5b
squid-debuginfo-3.5.20-17.el7_9.10.s390x.rpm SHA-256: 6d244f1945ede1accab10eea28cb81651ebc9fce31f4774145e495297329fb5b
squid-migration-script-3.5.20-17.el7_9.10.s390x.rpm SHA-256: 84da9ccc5f308c5a6e42c7dc2d3096983479003d971637114b05f42dc1dd6280
squid-sysvinit-3.5.20-17.el7_9.10.s390x.rpm SHA-256: 5cb346bc8cf1a52a7e0d26eab0135b1a4bad4f0271317acb44f1ba07e38c4491

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7

SRPM
squid-3.5.20-17.el7_9.10.src.rpm SHA-256: 6caadc8b302f34069bcc58566b1b940d4f15f060a32081ad6532d01d63299572
ppc64
squid-3.5.20-17.el7_9.10.ppc64.rpm SHA-256: 8426aae429d4b166975c384e230264e967bd777c95a0cb32ac86c3a875ff6699
squid-debuginfo-3.5.20-17.el7_9.10.ppc64.rpm SHA-256: 6fbf55e7f35a21b36ebfa0b2ea511c346c6b4d6549c7f436e1d60bd1dc7a1b6c
squid-debuginfo-3.5.20-17.el7_9.10.ppc64.rpm SHA-256: 6fbf55e7f35a21b36ebfa0b2ea511c346c6b4d6549c7f436e1d60bd1dc7a1b6c
squid-migration-script-3.5.20-17.el7_9.10.ppc64.rpm SHA-256: 334fb3d5580f23738486837ed6724059cecda668e3564cd7efd373874ede90fa
squid-sysvinit-3.5.20-17.el7_9.10.ppc64.rpm SHA-256: 14b24c7a6419aed4bd12b5e7e9a39469fa25fb68dccad346ec70172d1077f5f3

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7

SRPM
squid-3.5.20-17.el7_9.10.src.rpm SHA-256: 6caadc8b302f34069bcc58566b1b940d4f15f060a32081ad6532d01d63299572
ppc64le
squid-3.5.20-17.el7_9.10.ppc64le.rpm SHA-256: 3be561764ae4bfd1a70343551b157ebff957255fb834c7c7c3d369252c109954
squid-debuginfo-3.5.20-17.el7_9.10.ppc64le.rpm SHA-256: 6636e541de272cc63d14907075854ce133575b8617c3dc822716c18d10c4fc33
squid-debuginfo-3.5.20-17.el7_9.10.ppc64le.rpm SHA-256: 6636e541de272cc63d14907075854ce133575b8617c3dc822716c18d10c4fc33
squid-migration-script-3.5.20-17.el7_9.10.ppc64le.rpm SHA-256: 970e28d760419a39b2e72587ea2f3089e7f4bf34b0427766a4d8fe61b636b665
squid-sysvinit-3.5.20-17.el7_9.10.ppc64le.rpm SHA-256: fe71e081d21b9b9a6f00a43f2e9605b5fc0285e35cddf9837e254450b86ddaa3

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility