[squid-users] How to make sure my Squid has no known vulnerabilities?

Matus UHLAR - fantomas uhlar at fantomas.sk
Tue Jun 7 12:43:22 UTC 2022

On 06.06.22 19:21, roee klinger wrote:
>I am installing Squid in Docker (Debian Buster) using Aptitude, the current
>latest version that is being installed is Squid 4.6-1+deb10u6, today I was
>contacted by a client that noticed we are using the Squid version 4.6,
>which is an old version, and he mentioned that there are a few
>known vulnerabilities with this old version, mainly he was bothered by

= marked as fixed.


the same usually applies.

>I have checked the available Debian packages, and it seems I am indeed
>running the latest available version that is provided by Aptitude, which is
>Squid 4.6, it seems that to get Squid 5.5, I will have to use Debian
>Is the version of Squid that I am using backported with security patches

nearly all debian versions of nearly all packages contain security patched 
backported to installed versions.

you can check on https://security-tracker.debian.org/tracker/

