==========================================================================
Ubuntu Security Notice USN-7845-1
October 28, 2025

squid, squid3 vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 25.10
- Ubuntu 25.04
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

Squid would allow unintended access to sensitive information over the
network.

Software Description:
- squid: Web proxy cache server
- squid3: Web proxy cache server

Details:

Leonardo Giovannini discovered that Squid failed to redact HTTP
Authentication credentials in a default configuration. An attacker could
possibly use this issue to obtain sensitive information.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 25.10
  squid                           6.13-1ubuntu4.1

Ubuntu 25.04
  squid                           6.13-1ubuntu1.2

Ubuntu 24.04 LTS
  squid                           6.13-0ubuntu0.24.04.3

Ubuntu 22.04 LTS
  squid                           5.9-0ubuntu0.22.04.4

Ubuntu 20.04 LTS
  squid                           4.10-1ubuntu1.13+esm1
                                  Available with Ubuntu Pro

Ubuntu 18.04 LTS
  squid                           3.5.27-1ubuntu1.14+esm4
                                  Available with Ubuntu Pro
  squid3                          3.5.27-1ubuntu1.14+esm4
                                  Available with Ubuntu Pro

Ubuntu 16.04 LTS
  squid                           3.5.12-1ubuntu7.16+esm5
                                  Available with Ubuntu Pro
  squid3                          3.5.12-1ubuntu7.16+esm5
                                  Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-7845-1
  CVE-2025-62168

Package Information:
  https://launchpad.net/ubuntu/+source/squid/6.13-1ubuntu4.1
  https://launchpad.net/ubuntu/+source/squid/6.13-1ubuntu1.2
  https://launchpad.net/ubuntu/+source/squid/6.13-0ubuntu0.24.04.3
  https://launchpad.net/ubuntu/+source/squid/5.9-0ubuntu0.22.04.4

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to