ELSA-2025-14414

ELSA-2025-14414 - squid security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2025-09-29

Description


[7:3.5.20-17.0.7.13]
- Fixes CVE-2025-54574, add URN access disabling config options [Orabug: 38350105]

[7:3.5.20-17.0.5.13]
- Fixed cve 2023-46846 for http and icap request/response smuggling [Orabug: 37326730]


Related CVEs


CVE-2025-54574
CVE-2021-28651

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 7 (x86_64) squid-3.5.20-17.0.7.el7_9.13.src.rpm18063ef3554556660369828d8c2e709ca78ab96cfd9410f4219fe9bf79e8c7bc-ol7_x86_64_latest_ELS
squid-3.5.20-17.0.7.el7_9.13.x86_64.rpmf52a28b52a00fe95097baa66b3c787c2694bf986239f6ee6aab982040db28f39-ol7_x86_64_latest_ELS
squid-migration-script-3.5.20-17.0.7.el7_9.13.x86_64.rpmc2150301a0ee31662f2a4460a0f6c6ab239895ebf369c4d8ef1608accb355faf-ol7_x86_64_latest_ELS
squid-sysvinit-3.5.20-17.0.7.el7_9.13.x86_64.rpm4e9c37a5aa2a2887209b69ff7bc9d67d57f0a3bf933e979f88cf427c6773994c-ol7_x86_64_latest_ELS



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete