漏洞信息详情
Squid cachemgr.cgi非法链接漏洞
- CNNVD编号:CNNVD-199907-029
- 危害等级: 高危
- CVE编号:
CVE-1999-0710
- 漏洞类型:
设计错误
- 发布时间:
1999-07-25
- 威胁类型:
远程
- 更新时间:
2006-11-16
- 厂 商:
redhat - 漏洞来源:
Posted to BugTraq … -
漏洞简介
Red Hat Linux 5.2与6.0版本以及其他发行版本的Squid程序包存在漏洞。Squid程序包在公共网络目录中安装cachemgr.cgi,远程攻击者将其用作连接其它系统的媒介。
漏洞公告
Please see the referenced vendor advisories for more information and fixes.
National Science Foundation Squid Web Proxy 2.2
-
RedHat 5.2 (alpha): squid-2.2.STABLE4-5.alpha
ftp://updates.redhat.com/6.0/alpha/squid-2.2.STABLE4-5.alpha.rpm -
RedHat 5.2 (i386): squid-2.2.STABLE4-5.i386
ftp://updates.redhat.com/6.0/i386/squid-2.2.STABLE4-5.i386.rpm -
RedHat 5.2 (sparc): squid-2.2.STABLE4-5.sparc
ftp://updates.redhat.com/6.0/sparc/squid-2.2.STABLE4-5.sparc.rpm -
RedHat 6.0 (alpha): squid-2.2.STABLE4-0.5.2.alpha
ftp://updates.redhat.com/5.2/alpha/squid-2.2.STABLE4-0.5.2.alpha.rpm -
RedHat 6.0 (i386): squid-2.2.STABLE4-0.5.2.i386
ftp://updates.redhat.com/5.2/i386/squid-2.2.STABLE4-0.5.2.i386.rpm -
RedHat 6.0 (sparc): squid-2.2.STABLE4-0.5.2.sparc
ftp://updates.redhat.com/5.2/sparc/squid-2.2.STABLE4-0.5.2.sparc.rpm
参考网址
来源: XF
名称: http-cgi-cachemgr(2385)
链接:http://xforce.iss.net/xforce/xfdb/2385
来源: BID
名称: 2059
链接:http://www.securityfocus.com/bid/2059
来源: REDHAT
名称: RHSA-2005:489
链接:http://www.redhat.com/support/errata/RHSA-2005-489.html
来源: REDHAT
名称: RHSA-1999:025
链接:http://www.redhat.com/support/errata/RHSA-1999-025.html
来源: www.redhat.com
链接:http://www.redhat.com/support/errata/archives/rh52-errata-general.html#squid
来源: FEDORA
名称: FEDORA-2005-373
链接:http://www.redhat.com/archives/fedora-announce-list/2005-May/msg00025.html
来源: DEBIAN
名称: DSA-576
链接:http://www.debian.org/security/2004/dsa-576
来源: FEDORA
名称: FLSA-2006:152809
链接:http://fedoranews.org/updates/FEDORA–.shtml