[Git][security-tracker-team/security-tracker][master] Add CVE-2025-54574/squid

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 1 23:39:25 BST 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a5d43be2 by Salvatore Bonaccorso at 2025-08-02T00:38:59+02:00
Add CVE-2025-54574/squid

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -41,7 +41,9 @@ CVE-2025-54593 (FreshRSS is a free, self-hostable RSS aggregator. In versions 1.
 CVE-2025-54590 (webfinger.js is a TypeScript-based WebFinger client that runs in both  ...)
 	TODO: check
 CVE-2025-54574 (Squid is a caching proxy for the Web. In versions 6.3 and below, Squid ...)
-	TODO: check
+	- squid 6.5-1
+	NOTE: https://github.com/squid-cache/squid/security/advisories/GHSA-w4gv-vw3f-29g3
+	NOTE: https://github.com/squid-cache/squid/commit/a27bf4b84da23594150c7a86a23435df0b35b988 (SQUID_6_4)
 CVE-2025-54564 (uploadsm in ChargePoint Home Flex 5.5.4.13 does not validate a user-co ...)
 	NOT-FOR-US: uploadsm in ChargePoint Home Flex
 CVE-2025-53012 (MaterialX is an open standard for the exchange of rich material and lo ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a5d43be27d966447a9a520ffb2ac333a13660e4f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a5d43be27d966447a9a520ffb2ac333a13660e4f
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250801/52964e28/attachment.htm>


More information about the debian-security-tracker-commits mailing list