Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Squid package should be upgraded to v4.9

    Scheduled Pinned Locked Moved Cache/Proxy
    3 Posts 2 Posters 585 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • NetViciousN Offline
      NetVicious
      last edited by

      Check these CVS which they seem to be fixed on squid v4.9. There it's no 4.4.x (the current version pfSense has) with those fixes.
      CVE-2019-12526 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12526
      CVE-2019-18679 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18679
      CVE-2019-18678 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18678

      The first and second seem to be high impact.
      https://nsfocusglobal.com/advisory-squid-multiple-high-risk-vulnerability/

      ..//\/ e t . \/ i c i o u s ..

      1 Reply Last reply Reply Quote 0
      • jimpJ Offline
        jimp Rebel Alliance Developer Netgate
        last edited by

        pfSense 2.4.x is still on squid-3.5.27_3. pfSense 2.5.x is on squid-4.9.

        The "4.4.x" you are seeing is just the GUI package version and is actually 0.4.44_9, but that's not relevant to squid issues.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • NetViciousN Offline
          NetVicious
          last edited by

          Thanks for the clarification. But squid v3.5 has the same problem and at this moment doesn't has a fix.
          The last version of 3.5 branch it's 3.5.28 ant it's affected too.

          ..//\/ e t . \/ i c i o u s ..

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.