OpenSSL Advisory 2015-03-19

Amos Jeffries <[email protected]> Fri, 20 Mar 2015 20:27:45 +1300
Newsgroups gmane.comp.web.squid.announce
Message-ID <550BCBF1.10105__40502.3003383123$1426836543$gmane$org@treenet.co.nz>
As you may be aware a number of security vulnerabilities have just been
announced regarding OpenSSL.
 <https://openssl.org/news/secadv_20150319.txt>

Several of these potentially impact Squid with Denial of Service and
connection failure side effects when using HTTPS or the SSL-Bump feature
set.

All users of Squid HTTPS and SSL features are advised to restart Squid
after upgrading their OpenSSL library to a fixed version.


There will be no direct Squid advisory regarding this since the
vulnerability is in OpenSSL itself, not Squid.


Amos Jeffries
Squid Software Foundation
_______________________________________________
squid-announce mailing list
[email protected]
http://lists.squid-cache.org/listinfo/squid-announce