[squid-users] [SQUID] Last version for RHEL ?

Amos Jeffries squid3 at treenet.co.nz
Sun Jun 8 07:15:44 UTC 2025


On 6/06/25 21:36, Clément Paulet wrote:
> Hi,
> 
> Install went fine now sorry.
> 6.13 is installed, but it seems the vulnerability https://joshua.hu/ 
> squid-security-audit-35-0days-45-exploits are still present in this version.
> 
> How have you addressed this issue?

FYI, the above is **not** a single issue. The document covers over 50 
different CVEs in a range of Squid features.
* Many are fixed in Squid release prior to v6.13.
* Some are fixed in Squid v7.
* Some still awaiting formal fixes.

It depends on which of the issues still open in v6 series affect you 
particularly as to what you, the builder of Squid, need to do to avoid 
them. see the particular CVE documents for details.


Cheers
Amos



More information about the squid-users mailing list