[ubuntu/resolute-proposed] squid 7.2-2ubuntu1 (Accepted)

Renan Rodrigo rr at ubuntu.com
Wed Nov 26 19:40:16 UTC 2025


squid (7.2-2ubuntu1) resolute; urgency=medium

  * Merge with Debian unstable (LP: #2126018). Remaining changes:
    - d/usr.sbin.squid: Add sections for squid-deb-proxy and
      squidguard
    - d/p/90-cf.data.ubuntu.patch: Add refresh patterns for deb
      packaging
    - Use snakeoil certificates:
      + d/control: add ssl-cert to dependencies
      + d/p/99-ubuntu-ssl-cert-snakeoil.patch: add a note about ssl
        to the default config file
    - d/NEWS: drop the NIS basic auth helper (LP #1895694)
    - d/rules: halt build upon test failures.
    - d/rules: do not include additional configuration files during
      build time tests. This would lead to test failures due to missing
      paths.
    - d/t/upstream-test-suite: use installed squid binary for
      autopkgtest config file checks.
    - d/source_squid.py, d/rules: Add apport hook (LP #676141)
  * New changes:
    - d/squid-openssl.links: fix broken manpage link for squid-openssl.
  * Dropped changes:
    - d/p/0009-Fix-Werror-alloc-size-larger-than-on-GCC-12.patch:
      Fix FTBFS due to -Werror=alloc-size-larger-than on GCC 12.
      [ Applied upstream in version 7.0.2 ]
    - d/p/0010-Fix-Werror-sign-compare-on-GCC-13.patch: fix comparison
      between signed and unsigned values.
      [ Applied upstream in version 7.0.2 ]
    - lp-2125118-*: Fix FTBFS with GCC-15 (LP #2125118)
      [ Applied upstream in version 7.0.2 ]
    - debian/patches/CVE-2025-59362.patch: fix ASN.1 encoding of long SNMP OIDs
      in lib/snmplib/asn1.c. (CVE-2025-59362)
      [ Applied upstream in version 7.2 ]
    - d/p/CVE-2025-62168.patch: Add maskSensitiveInfo parameter to
      pack and pass it to packInto in src/HttpRequest.cc. Add maskSensitiveInfo
      to pack in src/HttpRequest.h. Adapt code with new parameter in
      src/client_side_reply.cc, and src/errorpage.cc. Remove request_hdr NULL
      assign in src/errorpage.h. (CVE-2025-62168)
      [ Applied upstream in version 7.2 ]
    - d/rules: disable LTO related compilation errors for ppc64el builds.
      [ No more needed in version 7.2-2 in resolute ]

squid (7.2-2) unstable; urgency=high

  [ Luigi Gangitano <luigi at debian.org> ]
  * debian/patches/0008-upstream-ab5cf0c36b538627c82b3989d6c87d1668c7e081.patch
    - Added upstream patch fixing error on CONNECT to hosts starting with
      digit

squid (7.2-1) unstable; urgency=high

  [ Amos Jeffries <amosjeffries at squid-cache.org> ]
  * New Upstream Release 7.2 (Closes: #1080997)
    Fixes: CVE-2025-62168. SQUID-2025:2 (Closes: #1118341)
    Fixes: CVE-2025-59362 (Closes: #1117048)

  * debian/watch
    - remove check for files no longer provided upstream

  * debian/control
    - support libkrb5 provided by krb5-multidev package

squid (7.1-1) unstable; urgency=high

  [ Amos Jeffries <amosjeffries at squid-cache.org> ]
  * New Upstream Release 7.1 (Closes: #1097927, #1015670)

  * Drop binaries removed upstream
    - ntlm_smb_lm_auth (Fixes: CVE-2025-21311)
    - squid-purge
    - squid-cgi
    - squidclient

  * Remove workaround for CVE-2024-45802, integrated upstream.

  * debian/patches/
    - refresh patches for new version

squid (6.13-2) unstable; urgency=low

  [ Amos Jeffries <amosjeffries at squid-cache.org> ]
  * debian/control
    - Bumped Standards-Version to 4.7.2, no change needed
    - Add Build-Dep on libcrypt-dev (Closes: #1106998)

  * debian/squid-openssl.links
    - Add symlink for man8 file

  * debian/squid.postrm
    - Remove no longer necessary workaround for Bug #984897

Date: Wed, 26 Nov 2025 15:36:40 -0300
Changed-By: Renan Rodrigo <rr at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/squid/7.2-2ubuntu1
-------------- next part --------------
Format: 1.8
Date: Wed, 26 Nov 2025 15:36:40 -0300
Source: squid
Built-For-Profiles: noudeb
Architecture: source
Version: 7.2-2ubuntu1
Distribution: resolute
Urgency: high
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Renan Rodrigo <rr at ubuntu.com>
Closes: 1015670 1080997 1097927 1106998 1117048 1118341
Launchpad-Bugs-Fixed: 2126018
Changes:
 squid (7.2-2ubuntu1) resolute; urgency=medium
 .
   * Merge with Debian unstable (LP: #2126018). Remaining changes:
     - d/usr.sbin.squid: Add sections for squid-deb-proxy and
       squidguard
     - d/p/90-cf.data.ubuntu.patch: Add refresh patterns for deb
       packaging
     - Use snakeoil certificates:
       + d/control: add ssl-cert to dependencies
       + d/p/99-ubuntu-ssl-cert-snakeoil.patch: add a note about ssl
         to the default config file
     - d/NEWS: drop the NIS basic auth helper (LP #1895694)
     - d/rules: halt build upon test failures.
     - d/rules: do not include additional configuration files during
       build time tests. This would lead to test failures due to missing
       paths.
     - d/t/upstream-test-suite: use installed squid binary for
       autopkgtest config file checks.
     - d/source_squid.py, d/rules: Add apport hook (LP #676141)
   * New changes:
     - d/squid-openssl.links: fix broken manpage link for squid-openssl.
   * Dropped changes:
     - d/p/0009-Fix-Werror-alloc-size-larger-than-on-GCC-12.patch:
       Fix FTBFS due to -Werror=alloc-size-larger-than on GCC 12.
       [ Applied upstream in version 7.0.2 ]
     - d/p/0010-Fix-Werror-sign-compare-on-GCC-13.patch: fix comparison
       between signed and unsigned values.
       [ Applied upstream in version 7.0.2 ]
     - lp-2125118-*: Fix FTBFS with GCC-15 (LP #2125118)
       [ Applied upstream in version 7.0.2 ]
     - debian/patches/CVE-2025-59362.patch: fix ASN.1 encoding of long SNMP OIDs
       in lib/snmplib/asn1.c. (CVE-2025-59362)
       [ Applied upstream in version 7.2 ]
     - d/p/CVE-2025-62168.patch: Add maskSensitiveInfo parameter to
       pack and pass it to packInto in src/HttpRequest.cc. Add maskSensitiveInfo
       to pack in src/HttpRequest.h. Adapt code with new parameter in
       src/client_side_reply.cc, and src/errorpage.cc. Remove request_hdr NULL
       assign in src/errorpage.h. (CVE-2025-62168)
       [ Applied upstream in version 7.2 ]
     - d/rules: disable LTO related compilation errors for ppc64el builds.
       [ No more needed in version 7.2-2 in resolute ]
 .
 squid (7.2-2) unstable; urgency=high
 .
   [ Luigi Gangitano <luigi at debian.org> ]
   * debian/patches/0008-upstream-ab5cf0c36b538627c82b3989d6c87d1668c7e081.patch
     - Added upstream patch fixing error on CONNECT to hosts starting with
       digit
 .
 squid (7.2-1) unstable; urgency=high
 .
   [ Amos Jeffries <amosjeffries at squid-cache.org> ]
   * New Upstream Release 7.2 (Closes: #1080997)
     Fixes: CVE-2025-62168. SQUID-2025:2 (Closes: #1118341)
     Fixes: CVE-2025-59362 (Closes: #1117048)
 .
   * debian/watch
     - remove check for files no longer provided upstream
 .
   * debian/control
     - support libkrb5 provided by krb5-multidev package
 .
 squid (7.1-1) unstable; urgency=high
 .
   [ Amos Jeffries <amosjeffries at squid-cache.org> ]
   * New Upstream Release 7.1 (Closes: #1097927, #1015670)
 .
   * Drop binaries removed upstream
     - ntlm_smb_lm_auth (Fixes: CVE-2025-21311)
     - squid-purge
     - squid-cgi
     - squidclient
 .
   * Remove workaround for CVE-2024-45802, integrated upstream.
 .
   * debian/patches/
     - refresh patches for new version
 .
 squid (6.13-2) unstable; urgency=low
 .
   [ Amos Jeffries <amosjeffries at squid-cache.org> ]
   * debian/control
     - Bumped Standards-Version to 4.7.2, no change needed
     - Add Build-Dep on libcrypt-dev (Closes: #1106998)
 .
   * debian/squid-openssl.links
     - Add symlink for man8 file
 .
   * debian/squid.postrm
     - Remove no longer necessary workaround for Bug #984897
Checksums-Sha1:
 21ad46671864976c26e6fcfe2c1b6e068adaa42c 2674 squid_7.2-2ubuntu1.dsc
 ebacd3da66c762d2eeb2fda3e9eb3012a3168477 2442224 squid_7.2.orig.tar.xz
 b9107ed7329b584962788c10f16fdda992f21011 54540 squid_7.2-2ubuntu1.debian.tar.xz
 677f6814dd1f2ec280afdd2d13da57cd77b53acc 9459 squid_7.2-2ubuntu1_source.buildinfo
Checksums-Sha256:
 d7300cb8130b49c8a99391004386b988f136f3f0f6050d2436bedbce5806d2cb 2674 squid_7.2-2ubuntu1.dsc
 5e077be1d83a9e696ce8d0d9e723b1273152207a091404be68a4b9a9e18c7003 2442224 squid_7.2.orig.tar.xz
 65bc49d4805b289eb9b29a1f74f35023c08b054799a90fd9a83917b336e59e2b 54540 squid_7.2-2ubuntu1.debian.tar.xz
 1a991c69f25d0b4ce3b04fb20460fd4356432c7afb1b460cc2ac853e079175ed 9459 squid_7.2-2ubuntu1_source.buildinfo
Files:
 611db25432666103d2478a44f96e9d71 2674 web optional squid_7.2-2ubuntu1.dsc
 7ccfe2f599b599f2de7ca18cb6b93951 2442224 web optional squid_7.2.orig.tar.xz
 ba4eb13ed0f71d4dcf0a3498ef30b9ae 54540 web optional squid_7.2-2ubuntu1.debian.tar.xz
 114c4224f856dcaf7201f090c17bc280 9459 web optional squid_7.2-2ubuntu1_source.buildinfo
Original-Maintainer: Luigi Gangitano <luigi at debian.org>
Vcs-Git: https://git.launchpad.net/~rr/ubuntu/+source/squid
Vcs-Git-Commit: c73cc6ef3ad6fb43bbd90999653fdba6ad83455b
Vcs-Git-Ref: refs/heads/merge-lp2126018-resolute


More information about the Resolute-changes mailing list