|
|
|
View Notes By
|
|
|
|
Other Documents
|
|
|
|
 |
Vulnerability Note VU#232881
Squid remote denial-of-service vulnerability
OverviewThe Squid Proxy server contains a vulnerability that may allow an attacker to create a denial-of-service condition that affects the Squid server and systems that rely on it.
I. DescriptionSquid Proxy Cache is a caching proxy that supports the HTTP, HTTPS, and FTP protocols. Squid can also be deployed as a reverse proxy.
From Squid Proxy Cache Security Update Advisory SQUID-2007:2
Due to incorrect bounds checking Squid is vulnerable to a denial of service check during some cache update reply processing.
This incorrect bounds checking occurs within the httpHeaderUpdate() function when processing cache update replies.
II. ImpactAn attacker who can access the Squid proxy may be able to cause the proxy server to crash. If the Squid proxy is deployed as a reverse proxy, the web servers relying on the proxy may also be affected.
III. SolutionUpdate
The Squid team has released patches 11780 and 11211 to address this issue. Administrators who obtain Squid from their operating system vendor should see the systems affected portion of this document for a partial list of affected vendors.
Restrict access
Restricting access to the Squid proxy via access control lists or firewall rules may prevent this vulnerability from being exploited by remote attackers..
Systems Affected
| Vendor | Status | Date Notified | Date Updated |
| Apple Computer, Inc. | Not Vulnerable | 11-Dec-2007 |
| Conectiva Inc. | Unknown | 10-Dec-2007 |
| Cray Inc. | Unknown | 10-Dec-2007 |
| Debian GNU/Linux | Unknown | 10-Dec-2007 |
| EMC Corporation | Unknown | 10-Dec-2007 |
| Engarde Secure Linux | Unknown | 10-Dec-2007 |
| F5 Networks, Inc. | Unknown | 10-Dec-2007 |
| Fedora Project | Unknown | 10-Dec-2007 |
| FreeBSD, Inc. | Unknown | 10-Dec-2007 |
| Fujitsu | Unknown | 10-Dec-2007 |
| Gentoo Linux | Unknown | 10-Dec-2007 |
| Hewlett-Packard Company | Unknown | 10-Dec-2007 |
| Hitachi | Unknown | 10-Dec-2007 |
| IBM Corporation | Unknown | 10-Dec-2007 |
| IBM Corporation (zseries) | Unknown | 10-Dec-2007 |
| IBM eServer | Unknown | 10-Dec-2007 |
| Ingrian Networks, Inc. | Unknown | 10-Dec-2007 |
| IPCop | Vulnerable | 11-Dec-2007 |
| Juniper Networks, Inc. | Unknown | 10-Dec-2007 |
| Mandriva, Inc. | Unknown | 10-Dec-2007 |
| Microsoft Corporation | Not Vulnerable | 11-Dec-2007 |
| MontaVista Software, Inc. | Unknown | 10-Dec-2007 |
| NEC Corporation | Unknown | 10-Dec-2007 |
| NetBSD | Not Vulnerable | 11-Dec-2007 |
| Nokia | Unknown | 10-Dec-2007 |
| Novell, Inc. | Unknown | 10-Dec-2007 |
| OpenBSD | Unknown | 10-Dec-2007 |
| Openwall GNU/*/Linux | Not Vulnerable | 11-Dec-2007 |
| QNX, Software Systems, Inc. | Unknown | 10-Dec-2007 |
| Red Hat, Inc. | Vulnerable | 11-Dec-2007 |
| Silicon Graphics, Inc. | Unknown | 10-Dec-2007 |
| Slackware Linux Inc. | Not Vulnerable | 10-Dec-2007 |
| SmoothWall | Unknown | 10-Dec-2007 |
| Sony Corporation | Unknown | 10-Dec-2007 |
| Squid | Vulnerable | 10-Dec-2007 |
| Sun Microsystems, Inc. | Unknown | 10-Dec-2007 |
| SUSE Linux | Vulnerable | 18-Jan-2008 |
| The SCO Group | Unknown | 10-Dec-2007 |
| Trustix Secure Linux | Unknown | 10-Dec-2007 |
| Turbolinux | Unknown | 10-Dec-2007 |
| Ubuntu | Unknown | 10-Dec-2007 |
| Unisys | Unknown | 10-Dec-2007 |
| Wind River Systems, Inc. | Unknown | 10-Dec-2007 |
References
http://www.squid-cache.org/Advisories/SQUID-2007_2.txt
http://wiki.squid-cache.org/SquidFaq/ReverseProxy
http://wiki.squid-cache.org/SquidFaq/SquidAcl#head-c87419712cac704d01cecc7da11cd02f489b6986
http://secunia.com/advisories/27910/
Credit
The Squid proxy team credits the Wikimedia Foundation for discovering this vulnerability. Adrian Chadd and Henrik Nordstrom are credited for authoring patches that address the issue.
This document was written by Ryan Giobbi.
Other Information
| Date Public: | 2007-11-27 |
| Date First Published: | 2007-12-10 |
| Date Last Updated: | 2008-01-18 |
| CERT Advisory: | |
| CVE-ID(s): | CVE-2007-6239 |
| NVD-ID(s): | CVE-2007-6239 |
| US-CERT Technical Alerts: | |
| Metric: | 7.51 |
| Document Revision: | 12 |
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|
|