Update information for CVE-2018-1000024/squid3
The Debian builds do Build-Depends on libexpat1-dev and libxml2-dev for ESI support since 3.1.0.14-2. The CVE-2018-1000024 problem is limited to Squid custom ESI parser, which vulnerable is present, but since Squid is built to use libxml2 or the libexpat XML parsers it does not have the problem in the resulting binary package. Mark it thus as unimportant.
Loading
Please register or sign in to comment