Format: 1.8 Date: Fri, 03 Feb 2017 14:09:18 -0500 Source: squid3 Binary: squid3 squid squid-dbg squid-common squidclient squid-cgi squid-purge Architecture: i386 Version: 3.5.12-1ubuntu7.3 Distribution: xenial Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: squid - Full featured Web Proxy cache (HTTP proxy) squid-cgi - Full featured Web Proxy cache (HTTP proxy) - control CGI squid-common - Full featured Web Proxy cache (HTTP proxy) - common files squid-dbg - Full featured Web Proxy cache (HTTP proxy) - Debug symbols squid-purge - Full featured Web Proxy cache (HTTP proxy) - control utility squid3 - Dummy transitional package. squidclient - Full featured Web Proxy cache (HTTP proxy) - control utility Changes: squid3 (3.5.12-1ubuntu7.3) xenial-security; urgency=medium . * SECURITY UPDATE: cookie data leak via If-Not-Modified HTTP conditional - debian/patches/CVE-2016-10002.patch: properly handle combination of If-Match and a Cache Hit in src/LogTags.h, src/client_side.cc, src/client_side_reply.cc, src/client_side_reply.h. - CVE-2016-10002 * SECURITY UPDATE: incorrect HTTP Request header comparison - debian/patches/CVE-2016-10003.patch: don't share private responses with collapsed client in src/client_side_reply.cc. - CVE-2016-10003 Checksums-Sha1: 971fe3e48753f04fbd48d5bf89d69bf6b2024afe 101640 squid-cgi-dbgsym_3.5.12-1ubuntu7.3_i386.ddeb 30465475cb729dad3d9b1e651accd5b2e0210d03 62914 squid-cgi_3.5.12-1ubuntu7.3_i386.deb bbf5f10942fdfbd0b3480a124ae617d5f0f865e1 10596364 squid-dbg_3.5.12-1ubuntu7.3_i386.deb f982ee20cd95873992a5edb0886d45dbff0ab78b 10379630 squid-dbgsym_3.5.12-1ubuntu7.3_i386.ddeb 1815253de69702e8191b4279e733486e60c35272 68410 squid-purge-dbgsym_3.5.12-1ubuntu7.3_i386.ddeb 4879bfb3ca03917b86d177eefd3e8d99a12bbe8f 53120 squid-purge_3.5.12-1ubuntu7.3_i386.deb 385cb6189c296af9bd9fbb64a3e07bdcf33dc000 2338522 squid_3.5.12-1ubuntu7.3_i386.deb 6f8f0d3bd928860a7227b8b26e2a5904dcccbc67 133304 squidclient-dbgsym_3.5.12-1ubuntu7.3_i386.ddeb 13ddf79b6ca76d03f754f51428db1f4d630553a6 65322 squidclient_3.5.12-1ubuntu7.3_i386.deb Checksums-Sha256: 1136ec60728eab44752046fc1c547da0461d85651deb841b7e8a65f68317fe65 101640 squid-cgi-dbgsym_3.5.12-1ubuntu7.3_i386.ddeb c04e6393a1ea44a48c23848f013115e4c4b15eee49451ae4fadc1c95fbcd4e21 62914 squid-cgi_3.5.12-1ubuntu7.3_i386.deb 5443a0ff9556508fcef52a5ddf5242683cce5a1d97a92fec6f9d3d5763a28919 10596364 squid-dbg_3.5.12-1ubuntu7.3_i386.deb ba802a28dc0083c80487a1072aacbba204c7eaa4244546b67ed2d82b40ac5307 10379630 squid-dbgsym_3.5.12-1ubuntu7.3_i386.ddeb 07ef79bd6f464ae985450c912ef2cd7442c461dfc71809e9a6107290b33c8fc2 68410 squid-purge-dbgsym_3.5.12-1ubuntu7.3_i386.ddeb f65b53d74d3b7a2283936c20d9fc3cf655c8bc7adaa555b22845bf065e12db9a 53120 squid-purge_3.5.12-1ubuntu7.3_i386.deb a29a532198e4cfee0de7fff953b0c44e994026baadb78f30464412e9d53b8ad6 2338522 squid_3.5.12-1ubuntu7.3_i386.deb 972bfdb72cbab80b1f1e54b127393bb59b3fb770c188192a3e1867a470a46aa9 133304 squidclient-dbgsym_3.5.12-1ubuntu7.3_i386.ddeb a2e1bbcc6976a59ae86ca3c9f90fd330fe5bb8dd61819caeed1046a50b8eb47c 65322 squidclient_3.5.12-1ubuntu7.3_i386.deb Files: 51e725f8269566fe8ec598d5d22432c1 101640 web extra squid-cgi-dbgsym_3.5.12-1ubuntu7.3_i386.ddeb 9b7bd488e0ec272d951236bf54a0f764 62914 web optional squid-cgi_3.5.12-1ubuntu7.3_i386.deb 2eb8e550890d028a391567a5347939c6 10596364 debug extra squid-dbg_3.5.12-1ubuntu7.3_i386.deb 5e0dd2223edacff43dd773868a638464 10379630 web extra squid-dbgsym_3.5.12-1ubuntu7.3_i386.ddeb f016af4c31a6c18d5c486fc5961f6e78 68410 web extra squid-purge-dbgsym_3.5.12-1ubuntu7.3_i386.ddeb fd09cc60945e2debf1fd0ce58473851c 53120 web optional squid-purge_3.5.12-1ubuntu7.3_i386.deb c0e512fe6ef265503fd085f28534f6a1 2338522 web optional squid_3.5.12-1ubuntu7.3_i386.deb d0f4759966ab46c19eabe6d6c0148b56 133304 web extra squidclient-dbgsym_3.5.12-1ubuntu7.3_i386.ddeb c5d4c3d7360458977cea524305108aeb 65322 web optional squidclient_3.5.12-1ubuntu7.3_i386.deb Original-Maintainer: Luigi Gangitano