[CLSA-2025:1763467263] Fix CVE(s): CVE-2025-62168
Type:
security
Severity:
Important
Release date:
2025-11-18 12:01:08 UTC
Description:
* SECURITY UPDATE: information disclosure via HTTP authentication credentials - debian/patches/CVE-2025-62168.patch: Fix bug causing visibility of proxy auth data to scripts by redacting credentials from error page code expansion output and mailto link generation - CVE-2025-62168
Updated packages:
  • squid_3.5.27-1ubuntu1.14+tuxcare.els10_amd64.deb
    sha:a2a178c0c13ffcce23bf622c415ff9d2de7e6a10
  • squid-cgi_3.5.27-1ubuntu1.14+tuxcare.els10_amd64.deb
    sha:641bb161372d100ee6c1482539a01fa6014b7c0f
  • squid-common_3.5.27-1ubuntu1.14+tuxcare.els10_all.deb
    sha:216ad0a811c5d5e1b19d511ed6386163f40a6f03
  • squid-purge_3.5.27-1ubuntu1.14+tuxcare.els10_amd64.deb
    sha:370ed074568c2552a05bdf7d97caca7f94e25a77
  • squid3_3.5.27-1ubuntu1.14+tuxcare.els10_all.deb
    sha:6730be1be910fbc935b04b3b49d663eeeeb709f9
  • squidclient_3.5.27-1ubuntu1.14+tuxcare.els10_amd64.deb
    sha:4a87eee75a66d44d4fe343d1219480192fc2b847
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.