[squid-users] [squid 3.5.5] security Update Advisory SQUID-2016:2

Amos Jeffries squid3 at treenet.co.nz
Wed Feb 24 21:14:23 UTC 2016


On 25/02/2016 7:21 a.m., Yuri Voinov wrote:
> 
> Squid's upgrade is the best solution.
> 
> 24.02.16 22:13, Paul Martin пишет:
>> Hello,
> 
>> I have squid 3.5.5, I see  Security Update Advisory SQUID-2016:2:
>> You suggest 2 solutions on
> http://www.squid-cache.org/Advisories/SQUID-2016_2.txt
>> --
>> 1)_add in squid.conf: _
>> acl Vary rep_header Vary
>> store_miss deny Vary
>> --
>> _2) or add in squid.conf :
>> _cache deny all
>> --
>> What's the best solution for parent squid ? for child squid ?
>> Where should i put these lines in squid.conf ?


As Yuri said upgrade is best.

Both the possible workarounds will seriously degrade your bandwidth
performance and are only usable if you are happy with no caching
happening OR if you are already suffering from this issue and cant
upgrade. They are provided for completeness as there are a few who might
be okay with that.

Amos


More information about the squid-users mailing list