Skip to content

Apply security fixes from Squid 6 to frontier-squid-5.9-2

Carl Vuosalo requested to merge fix-vulnerabilities into master

Squid 6.6 contains fixes for several security vulnerabilities. Unfortunately, it also has a bug related to collapsed forwarding, so it is not usable for frontier-squid. To quickly address the vulnerabilities, the security fixes from Squid 6 are backported to frontier-squid-5.9-2. The fixes are for:

Two vulnerabilities are addressed by disabling Gopher and TRACE requests in the squid.conf.proto file:

Edited by Carl Vuosalo

Merge request reports