Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Mon, 29 Oct 2018 07:43:50 +1300
From: Amos Jeffries <squid3@...enet.co.nz>
To: oss-security@...ts.openwall.com
Subject: Re: Squid Proxy multiple vulnerabilities

On 29/10/18 6:21 AM, Hanno Böck wrote:
> On Mon, 29 Oct 2018 05:13:40 +1300
> Amos Jeffries wrote:
> 
>> <http://www.squid-cache.org/Advisories/SQUID-2018_4.txt>
> 
> That gives a 404.

YMMV as third-party mirrors are still updating in some parts.

> 
> Also there's another yet unfixed vulnerability: The webpage and the
> downloads are not using HTTPS, which makes them vulnerable to
> man-in-the-middle attacks ;-)
> 

This is intentional. We do not restrict to those able to access HTTPS.

Also, notice that issue is most relevant to installations routinely
MITM'ing the HTTPS protocol.


AYJ



Download attachment "signature.asc" of type "application/pgp-signature" (834 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.