SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |    Help    |   

SecurityTracker
Archives


Your Ad Here
 
Click to Sign Up
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com

Sign Up!





Category:  Application (Web Server/CGI)  >  Squid Vendors:  Squid-cache.org
Squid Cache Update Reply Processing Bug Lets Remote Users Deny Service
SecurityTracker Alert ID:  1019036
SecurityTracker URL:  http://securitytracker.com/id?1019036
CVE Reference:  CVE-2007-6239 ,  CVE-2008-1612   (Links to External Site)
Updated:  Apr 9 2008
Original Entry Date:  Dec 4 2007
Impact:  Denial of service via network
Fix Available:  Yes   Vendor Confirmed:  Yes  
Version(s): prior to 2.6.STABLE17
Description:  A vulnerability was reported in Squid. A remote user can cause denial of service conditions.

A remote user that is trusted to use the proxy service can trigger a flaw in the processing of cache update replies to cause the target service to crash.

The Wikimedia Foundation reported this vulnerability.

Impact:  A remote user can cause the target service to crash.
Solution:  The vendor issued a fixed version (2.6.STABLE17).

Squid-2.6:

http://www.squid-cache.org/Versions/v2/2.6/changesets/11780.patch

Squid-3:

http://www.squid-cache.org/Versions/v3/3.0/changesets/11211.patch

The above fix for version 2.6 introduced a new denial of service vulnerability [CVE-2008-1612], which was corrected in 2008:

http://www.squid-cache.org/Versions/v2/2.6/changesets/11882.patch

Squid 2.6.STABLE18 contains the additional fix.

The Squid advisory is available at:

http://www.squid-cache.org/Advisories/SQUID-2007_2.txt

Vendor URL:  www.squid-cache.org/Advisories/SQUID-2007_2.txt (Links to External Site)
Cause:  Boundary error
Underlying OS:  Linux (Any), UNIX (Any)

Message History:   This archive entry has one or more follow-up message(s) listed below.
Dec 18 2007 (Red Hat Issues Fix) Squid Cache Update Reply Processing Bug Lets Remote Users Deny Service   (bugzilla@redhat.com)
Red Hat has released a fix for Red Hat Enterprise Linux 2.1, 3, 4, and 5.
Apr 9 2008 (Red Hat Issues Fix) Squid Cache Update Reply Processing Bug Lets Remote Users Deny Service   (bugzilla@redhat.com)
Red Hat has released a fix for Red Hat Enterprise Linux 2.1, 3, 4, and 5.



 Source Message Contents

Date:  Mon, 3 Dec 2007 23:20:30 -0500
Subject:  Squid Proxy Cache

 
 
http://www.squid-cache.org/Advisories/SQUID-2007_2.txt
 
__________________________________________________________________
 
      Squid Proxy Cache Security Update Advisory SQUID-2007:2
__________________________________________________________________
 
Advisory ID:            SQUID-2007:2
Date:                   November 27, 2007
Summary:                Denial of service in cache updates
Affected versions:      Squid 2.X (2.0 -> 2.6.STABLE16); Squid-3.
Fixed in version:       Squid 2.6.STABLE17;
			November 28 Squid-2 snapshot
			November 28 Squid-3 snapshot
Author:			Adrian Chadd
Thanks:			Wikimedia Foundation
 
__________________________________________________________________
 
     http://www.squid-cache.org/Advisories/SQUID-2007_2.txt
__________________________________________________________________
 
Problem Description:
 
 Due to incorrect bounds checking Squid is vulnerable to
 a denial of service check during some cache update reply
 processing.
 
__________________________________________________________________
 
Severity:
 
 This problem allows any client trusted to use the service to
 perform a denial of service attack on the Squid service.
 
__________________________________________________________________
 
Updated Packages:
 
 This bug is fixed by Squid version 2.6.STABLE17 and by the November
 28 snapshots of Squid-2 and Squid-3.
 
 In addition, a patch addressing this problem can be found in
 our patch archive for version Squid-2.6:
 
  http://www.squid-cache.org/Versions/v2/2.6/changesets/11780.patch
 
 And for Squid-3:
 
  http://www.squid-cache.org/Versions/v3/3.0/changesets/11211.patch
 
 If you are using a prepackaged version of Squid then please refer
 to the package vendor for availability information on updated
 packages.
 
__________________________________________________________________
 
Determining if your version is vulnerable:
 
 All Squid-2.X versions up to, and including 2.6.STABLE16 are
 vulnerable.
 
 All Squid-3 snapshots and prereleases up to the November 28
 snapshot are vulnerable.
 
__________________________________________________________________
 
Workarounds:
 
 There are no workarounds.
 
__________________________________________________________________
 
Thanks to:
 
 Thanks go to the Wikimedia Foundation for helping identify the issue
 and testing the proposed resolution of the issue.
 
 Thanks to Adrian Chadd for the Squid-2 fix.
 
 Thanks to Henrik Nordstrom for the Squid-3 fix.
 
__________________________________________________________________
 
Contact details for the Squid project:
 
 For installation / upgrade support on binary packaged versions
 of Squid: Your first point of contact should be your binary
 package vendor.
 
 If your install and build Squid from the original Squid sources
 then the squid-users@squid-cache.org mailing list is your primary
 support point. See <http://www.squid-cache.org/mailing-lists.html>
 for subscription details.
 
 For reporting of non-security bugs in the latest STABLE release
 the squid bugzilla database should be used
 <http://www.squid-cache.org/bugs/>.
 
 For reporting of security sensitive bugs send an email to the
 squid-bugs@squid-cache.org mailing list. It's a closed list
 (though anyone can post) and security related bug reports are
 treated in confidence until the impact has been established.
 
__________________________________________________________________
 
Revision history:
 
 2007-11-26 14:40 GMT+9 Initial version
__________________________________________________________________
END
 
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us   |    Help

Copyright 2007, SecurityGlobal.net LLC