[squid-announce] [ADVISORY] SQUID-2016:4 Denial of Service issue in HTTP Response processing.

2016-04-02 Thread Amos Jeffries
post) and security related bug reports are treated in confidence until the impact has been established. __ Credits: This vulnerability was reported by Santiago R. Rincon of Debian. Fixed by Amos Jeffries from Tree

[squid-announce] Squid 3.5.16 is available

2016-04-02 Thread Amos Jeffries
ftp://ftp.squid-cache.org/pub/archive/3.5/ or the mirrors. For a list of mirror sites see http://www.squid-cache.org/Download/http-mirrors.html http://www.squid-cache.org/Download/mirrors.html If you encounter any issues with this release please file a bug report. htt

[squid-announce] Squid 4.0.10 beta is available

2016-05-09 Thread Amos Jeffries
ues with this release please file a bug report. http://bugs.squid-cache.org/ Amos Jeffries ___ squid-announce mailing list squid-announce@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-announce

[squid-announce] [ADVISORY] SQUID-2016:7 Cache poisoning issue in HTTP Request handling

2016-05-09 Thread Amos Jeffries
_ Credits: The vulnerability was reported by Jianjun Chen from Tsinghua University. Fixed by Amos Jeffries from Treehouse Networks Ltd. __ Revision history: 2016-04-15 10:54:39 UTC Initial Report 2016-05-02 10:51:18 UTC Patch R

[squid-announce] [ADVISORY] SQUID-2016:8 Header smuggling issue in HTTP Request processing

2016-05-09 Thread Amos Jeffries
l the impact has been established. __ Credits: The vulnerability was reported by Jianjun Chen from Tsinghua University. Fixed by Amos Jeffries from Treehouse Networks Ltd. __ Revision history: 2016-04-26 09:29:13 UTC Initial Report

[squid-announce] [ADVISORY SQUID-2016:6 Multiple issues in ESI processing.

2016-04-21 Thread Amos Jeffries
The vulnerability was reported by CESG. Fixed by Amos Jeffries, Treehouse Networks Ltd. __ Revision history: 2016-04-15 10:54:39 GMT Initial Report 2016-04-20 03:54:54 GMT Patches Released 2016-04-20 13:42:00 GMT Packages

[squid-announce] Squid 3.5.20 is available

2016-07-04 Thread Amos Jeffries
.html If you encounter any issues with this release please file a bug report. http://bugs.squid-cache.org/ Amos Jeffries ___ squid-announce mailing list squid-announce@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-announce

[squid-announce] Squid 4.0.13 beta is available

2016-08-08 Thread Amos Jeffries
with this release please file a bug report. http://bugs.squid-cache.org/ Amos Jeffries ___ squid-announce mailing list squid-announce@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-announce

[squid-announce] Squid 3.5.21 is available

2016-09-11 Thread Amos Jeffries
he.org/Download/http-mirrors.html http://www.squid-cache.org/Download/mirrors.html If you encounter any issues with this release please file a bug report. http://bugs.squid-cache.org/ Amos Jeffries ___ squid-announce mailing list squid-announce@lists.

[squid-announce] Squid 4.0.14 beta is available

2016-09-11 Thread Amos Jeffries
any issues with this release please file a bug report. http://bugs.squid-cache.org/ Amos Jeffries ___ squid-announce mailing list squid-announce@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-announce

[squid-announce] Squid 4.0.16 beta is available

2016-10-30 Thread Amos Jeffries
/archive/4/ or the mirrors. For a list of mirror sites see http://www.squid-cache.org/Download/http-mirrors.html http://www.squid-cache.org/Download/mirrors.html If you encounter any issues with this release please file a bug report. http://bugs.squid-cache.org/ Amo

[squid-announce] Squid Signing key rollover

2016-10-28 Thread Amos Jeffries
The PGP key I use to sign Squid binaries and associated files is being refreshed. Squid-4.0.16 and later releases will be signed with the key; Email: Amos Jeffries (Squid Signing Key) <squ...@treenet.co.nz> Fingerprint: B068 84ED B779 C89B 044E 64E3 CD6D BF8E F3B1 7D3E This new Squid

[squid-announce] Squid 3.5.22 is available

2016-10-12 Thread Amos Jeffries
-cache.org/pub/archive/3.5/ or the mirrors. For a list of mirror sites see http://www.squid-cache.org/Download/http-mirrors.html http://www.squid-cache.org/Download/mirrors.html If you encounter any issues with this release please file a bug report. http://bugs.squid-

[squid-announce] Squid 4.0.15 beta is available

2016-10-12 Thread Amos Jeffries
://www.squid-cache.org/Download/http-mirrors.html http://www.squid-cache.org/Download/mirrors.html If you encounter any issues with this release please file a bug report. http://bugs.squid-cache.org/ Amos Jeffries ___ squid-announce mailing list squid-announce

[squid-announce] Squid 4.0.17 beta is available

2016-12-17 Thread Amos Jeffries
a bug report. http://bugs.squid-cache.org/ Amos Jeffries ___ squid-announce mailing list squid-announce@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-announce

[squid-announce] Squid 3.5.25 is available

2017-04-07 Thread Amos Jeffries
/www.squid-cache.org/Download/mirrors.html If you encounter any issues with this release please file a bug report. http://bugs.squid-cache.org/ Amos Jeffries ___ squid-announce mailing list squid-announce@lists.squid-cache.org http://lists.squid-cache.or

[squid-announce] Squid 4.0.20 beta is available

2017-06-13 Thread Amos Jeffries
://www.squid-cache.org/Download/mirrors.html If you encounter any issues with this release please file a bug report. http://bugs.squid-cache.org/ Amos Jeffries ___ squid-announce mailing list squid-announce@lists.squid-cache.org http://lists.squid

[squid-announce] Squid 3.5.26 is available

2017-06-13 Thread Amos Jeffries
he.org/pub/archive/3.5/ or the mirrors. For a list of mirror sites see http://www.squid-cache.org/Download/http-mirrors.html http://www.squid-cache.org/Download/mirrors.html If you encounter any issues with this release please file a bug report. http://bugs.squid-cache.org/ Amo

[squid-announce] Squid 4.0.22 beta is available

2017-12-09 Thread Amos Jeffries
ase please file a bug report. http://bugs.squid-cache.org/ Amos Jeffries ___ squid-announce mailing list squid-announce@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-announce

[squid-announce] Squid 4.0.25 beta is available

2018-06-16 Thread Amos Jeffries
ache.org/Download/mirrors.html If you encounter any issues with this release please file a bug report. http://bugs.squid-cache.org/ Amos Jeffries ___ squid-announce mailing list squid-announce@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-announce

[squid-announce] Squid 4.1 is available

2018-07-03 Thread Amos Jeffries
encounter any issues with this release please file a bug report. http://bugs.squid-cache.org/ Amos Jeffries ___ squid-announce mailing list squid-announce@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-announce

[squid-announce] RFC: Squid ESI processor changes

2018-01-18 Thread Amos Jeffries
(a) does setting it explicitly to either of the other parsers cause a large impact on your traffic performance? Yes/No If yes, which did you choose? ... and how much of an impact was seen? If you are not comfortable answering this to the squid-dev mailing list please feel free to send your re

[squid-announce] Squid 4.0.23 beta is available

2018-01-22 Thread Amos Jeffries
e.org/Download/http-mirrors.html http://www.squid-cache.org/Download/mirrors.html If you encounter any issues with this release please file a bug report. http://bugs.squid-cache.org/ Amos Jeffries ___ squid-announce mailing list squid-announce@lists.s

[squid-announce] Squid 4.2 is available

2018-08-10 Thread Amos Jeffries
/Download/mirrors.html If you encounter any issues with this release please file a bug report. http://bugs.squid-cache.org/ Amos Jeffries ___ squid-announce mailing list squid-announce@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-announce

[squid-announce] [ADVISORY] SQUID-2018:2 Denial of Service issue in HTTP Message processing

2018-01-22 Thread Amos Jeffries
urity related bug reports are treated in confidence until the impact has been established. __ Credits: The initial issue was reported by Louis Dion-Marcil on behalf of GoSecure. Fixed by Amos Jeffries from Treehouse Networks Ltd. __

[squid-announce] [ADVISORY] SQUID-2018:3 Denial of Service issue in ESI Response processing.

2018-04-18 Thread Amos Jeffries
__ Squid Proxy Cache Security Update Advisory SQUID-2018:3 __ Advisory ID:SQUID-2018:3 Date: April 18, 2018 Summary:Denial of

[squid-announce] Squid 4.0.24 beta is available

2018-03-18 Thread Amos Jeffries
/archive/4/ or the mirrors. For a list of mirror sites see http://www.squid-cache.org/Download/http-mirrors.html http://www.squid-cache.org/Download/mirrors.html If you encounter any issues with this release please file a bug report. http://bugs.squid-cache.org/ Amos Jeffries

[squid-announce] [ADVISORY] SQUID-2018:5 Denial of Service issue in SNMP processing

2018-10-28 Thread Amos Jeffries
__ Squid Proxy Cache Security Update Advisory SQUID-2018:5 __ Advisory ID:SQUID-2018:5 Date: October 28, 2018 Summary:Denial of

[squid-announce] [ADVISORY] SQUID-2018:4 Cross-Site Scripting issue in TLS error processing

2018-10-28 Thread Amos Jeffries
__ Squid Proxy Cache Security Update Advisory SQUID-2018:4 __ Advisory ID:SQUID-2018:4 Date: October 28, 2018 Summary:Cross-Site

[squid-announce] Squid-4.5 is available

2019-01-04 Thread Amos Jeffries
ttp://bugs.squid-cache.org/ Amos Jeffries ___ squid-announce mailing list squid-announce@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-announce

[squid-announce] Squid 4.6 is available

2019-02-26 Thread Amos Jeffries
. For a list of mirror sites see http://www.squid-cache.org/Download/http-mirrors.html http://www.squid-cache.org/Download/mirrors.html If you encounter any issues with this release please file a bug report. http://bugs.squid-cache.org/ Amos Jeffries

[squid-announce] [ADVISORY] SQUID-2019:3 Denial of Service in HTTP Digest Authentication processing

2019-07-13 Thread Amos Jeffries
s vulnerability was discovered by Jeriko One . Fixed by Amos Jeffries of Treehouse Networks Ltd. __ Revision history: 2019-05-14 14:56:49 UTC Initial Report 2019-06-05 15:52:17 UTC CVE Assignment 2019-06-08

[squid-announce] [ADVISORY] SQUID-2019:2 Denial of Service in HTTP Basic Authentication processing

2019-07-13 Thread Amos Jeffries
ecurity related bug reports are treated in confidence until the impact has been established. __ Credits: This vulnerability was discovered by Jeriko One . Fixed by Amos Jeffrie

[squid-announce] [ADVISORY] SQUID-2019:6 Multiple Cross-Site Scripting issues in cachemgr.cgi

2019-07-13 Thread Amos Jeffries
list (though anyone can post) and security related bug reports are treated in confidence until the impact has been established. __ Credits: This vulnerability was discovered by Anil Pazvant. Fixed by Amos Jeff

[squid-announce] Squid 4.8 is available

2019-07-13 Thread Amos Jeffries
mirrors. For a list of mirror sites see http://www.squid-cache.org/Download/http-mirrors.html http://www.squid-cache.org/Download/mirrors.html If you encounter any issues with this release please file a bug report. http://bugs.squid-cache.org/ Amos Jeffries

[squid-announce] [ADVISORY] SQUID-2019:1 Denial of Service issue in cachemgr.cgi

2019-07-13 Thread Amos Jeffries
pact has been established. __ Credits: This vulnerability was discovered by Alex Rousskov of The Measurement Factory. Fixed by Amos Jeffries from Treehouse Networks Ltd. __ Revision history:

[squid-announce] [ADVISORY] SQUID-2019:8 Multiple issues in URI processing

2019-11-08 Thread Amos Jeffries
ulnerability was discovered by Jeriko One . The Denial of Service vulnerability was discovered by Kristoffer Danielsson. Fixed by Amos Jeffries, Treehouse Networks Ltd. __ Revision history: 2019-05-14 14:56:49 UTC Initial Report

[squid-announce] [ADVISORY] SQUID-2019:9 Cross-Site Request Forgery issue in HTTP Request processing

2019-11-08 Thread Amos Jeffries
This vulnerability was discovered by Kristoffer Danielsson. Fixed by Amos Jeffries of Treehouse Networks Ltd. __ Revision history: 2019-06-26 21:43:49 UTC Initial Report 2019-07-12 03:08:00 UTC Patches Released 2019-11-04 13:43

[squid-announce] [ADVISORY] SQUID-2019:7 Heap Overflow issue in URN processing

2019-11-08 Thread Amos Jeffries
__ Squid Proxy Cache Security Update Advisory SQUID-2019:7 __ Advisory ID:SQUID-2019:7 Date: November 5, 2019 Summary:Heap

[squid-announce] [ADVISORY] SQUID-2019:10 HTTP Request Splitting issue in HTTP message processing

2019-11-08 Thread Amos Jeffries
lero from Makina Corpus). Fixed by Amos Jeffries of Treehouse Networks Ltd. __ Revision history: 2019-07-24 11:52:51 UTC Initial Report 2019-09-11 02:52:52 UTC Patches Released 2019-11-04 13:

[squid-announce] Squid 4.9 is available

2019-11-08 Thread Amos Jeffries
l http://www.squid-cache.org/Download/mirrors.html If you encounter any issues with this release please file a bug report. http://bugs.squid-cache.org/ Amos Jeffries ___ squid-announce mailing list squid-announce@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-announce

[squid-announce] [ADVISORY] SQUID-2019:11 Information Disclosure issue in HTTP Digest Authentication

2019-11-08 Thread Amos Jeffries
__ Squid Proxy Cache Security Update Advisory SQUID-2019:11 __ Advisory ID:SQUID-2019:11 Date: November 05, 2019 Summary:

[squid-announce] [ADVISORY] SQUID-2020:3 Buffer Overflow issue in ext_lm_group_acl helper.

2020-02-03 Thread Amos Jeffries
__ Squid Proxy Cache Security Update Advisory SQUID-2020:3 __ Advisory ID:SQUID-2020:3 Date: February 02, 2020 Summary:Buffer

[squid-announce] [ADVISORY] SQUID-2020:2 Information Disclosure issue in FTP Gateway.

2020-02-03 Thread Amos Jeffries
__ Squid Proxy Cache Security Update Advisory SQUID-2020:2 __ Advisory ID:SQUID-2020:2 Date: February 02, 2020 Summary:Information

[squid-announce] Squid 4.10 is available

2020-02-03 Thread Amos Jeffries
irrors.html http://www.squid-cache.org/Download/mirrors.html If you encounter any issues with this release please file a bug report. http://bugs.squid-cache.org/ Amos Jeffries ___ squid-announce mailing list squid-announce@lists.squid-cache.org

[squid-announce] [ADVISORY] SQUID-2020:1 Improper Input Validation issues in HTTP Request processing.

2020-02-03 Thread Amos Jeffries
iscovered by Regis Leroy (regilero from Makina Corpus). Denial of Service and Remote Code Execution vulnerability was discovered by Guido Vranken. Fixed by Amos Jeffries of Treehouse Networks Ltd. and Guido Vranken. __ Revi

[squid-announce] [ADVISORY] SQUID-2019:4 Multiple Issues in HTTP Request processing

2020-04-18 Thread Amos Jeffries
act has been established. __ Credits: This vulnerability was discovered by Jeriko One . Fixed by Amos Jeffries of Treehouse Networks Ltd. __ Revision history: 2019-05-14 14:56:49 UTC Initial Report 2019-06-23 15:15:56 UTC P

[squid-announce] [ADVISORY] SQUID-2020:4 Multiple issues in HTTP Digest authentication

2020-04-23 Thread Amos Jeffries
__ Squid Proxy Cache Security Update Advisory SQUID-2020:4 __ Advisory ID:SQUID-2020:4 Date: April 23, 2020 Summary:Multiple

[squid-announce] Squid 5.0.2 beta is available

2020-04-23 Thread Amos Jeffries
tp://bugs.squid-cache.org/ Amos Jeffries ___ squid-announce mailing list squid-announce@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-announce

[squid-announce] Squid 4.11 is available

2020-04-23 Thread Amos Jeffries
html If you encounter any issues with this release please file a bug report. http://bugs.squid-cache.org/ Amos Jeffries ___ squid-announce mailing list squid-announce@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-announce

[squid-announce] Squid 4.13 is available

2020-08-23 Thread Amos Jeffries
any issues with this release please file a bug report. http://bugs.squid-cache.org/ Amos Jeffries ___ squid-announce mailing list squid-announce@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-announce

[squid-announce] [ADVISORY] SQUID-2020:9 Denial of Service processing Cache Digest Response

2020-08-23 Thread Amos Jeffries
__ Squid Proxy Cache Security Update Advisory SQUID-2020:9 __ Advisory ID: | SQUID-2020:9 Date: | August 23, 2020 Summary: | Denial of

[squid-announce] [ADVISORY] SQUID-2020:8 HTTP(S) Request Splitting

2020-08-23 Thread Amos Jeffries
established. ______ Credits: This vulnerability was discovered by Regis Leroy (regilero from Makina Corpus). Fixed by Amos Jeffries of Treehouse Networks Ltd. __ R

[squid-announce] [ADVISORY] SQUID-2020:10 HTTP(S) Request Smuggling

2020-08-23 Thread Amos Jeffries
established. __ Credits: This vulnerability was discovered by Amit Klein of Safebreach. Fixed by Amos Jeffries of Treehouse Networks Ltd. _

[squid-announce] [ADVISORY] SQUID-2020:5 Denial of Service when using SMP cache

2020-06-19 Thread Amos Jeffries
__ Squid Proxy Cache Security Update Advisory SQUID-2020:5 __ Advisory ID: | SQUID-2020:5 Date: | June 19, 2020 Summary: | Denial

[squid-announce] Squid 4.12 is available

2020-06-19 Thread Amos Jeffries
If you encounter any issues with this release please file a bug report. http://bugs.squid-cache.org/ Amos Jeffries ___ squid-announce mailing list squid-announce@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-announce

[squid-announce] Squid 5.0.3 beta is available

2020-06-19 Thread Amos Jeffries
port. http://bugs.squid-cache.org/ Amos Jeffries ___ squid-announce mailing list squid-announce@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-announce

[squid-announce] [ADVISORY] SQUID-2020:6 Denial of Service issue in TLS Handshake

2020-06-19 Thread Amos Jeffries
__ Squid Proxy Cache Security Update Advisory SQUID-2020:6 __ Advisory ID: | SQUID-2020:6 Date: | June 19, 2020 Summary: | Denial of

[squid-announce] [ADVISORY] SQUID-2020:7 Cache Poisoning Issue in HTTP Request processing

2020-06-26 Thread Amos Jeffries
__ Squid Proxy Cache Security Update Advisory SQUID-2020:7 __ Advisory ID: | SQUID-2020:7 Date: | June 26, 2020 Summary: | Cache

[squid-announce] [ADVISORY] SQUID-2020:11 HTTP Request Smuggling

2021-05-10 Thread Amos Jeffries
(though anyone can post) and security related bug reports are treated in confidence until the impact has been established. __ Credits: This vulnerability was discovered by Jianjun C

[squid-announce] Squid 4.16 is available

2021-07-21 Thread Amos Jeffries
/ or the mirrors. For a list of mirror sites see http://www.squid-cache.org/Download/http-mirrors.html http://www.squid-cache.org/Download/mirrors.html If you encounter any issues with this release please file a bug report. http://bugs.squid-cache.org/ Amos Jeffries