Squid 畸形http 响应解析缓存攻击漏洞

漏洞信息详情

Squid 畸形http 响应解析缓存攻击漏洞

漏洞简介

Squid(全称Squid Cache)是一套代理服务器和Web缓存服务器软件。该软件提供缓存万维网、过滤流量、代理上网等功能。
Squid在处理畸形HTTP请求和应答时存在问题,远程攻击者可以利用这个漏洞在squid缓存中放置不安全或错误的内容。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Squid Web Proxy Cache 2.4 .STABLE7
Mandrake squid-2.4.STABLE7-1.2.M82mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake squid-2.4.STABLE7-2.1.C21mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake squid-2.4.STABLE7-2.1.C21mdk.x86_64.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake squid-2.4.STABLE7-2.2.C21mdk.i586.rpm
Mandrake Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php
Mandrake squid-2.4.STABLE7-2.2.C21mdk.x86_64.rpm
Mandrake Corporate Server 2.1/x86_64
http://www.mandrakesecure.net/en/ftp.php
Mandrake squid-2.4.STABLE7-2.3.C21mdk.i586.rpm
Mandrake Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php
Mandrake squid-2.4.STABLE7-2.3.C21mdk.x86_64.rpm
Mandrake Corporate Server 2.1/x86_64
http://www.mandrakesecure.net/en/ftp.php
Mandrake squid-2.4.STABLE7-2.4.C21mdk.i586.rpm
Mandrake Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php
Mandrake squid-2.4.STABLE7-2.4.C21mdk.x86_64.rpm
Mandrake Corporate Server 2.1/x86_64
http://www.mandrakesecure.net/en/ftp.php
Mandrake squid-2.4.STABLE7-2.5.C21mdk.i586.rpm
Mandrake Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php
Mandrake squid-2.4.STABLE7-2.5.C21mdk.x86_64.rpm
Mandrake Corporate Server 2.1/x86_64
http://www.mandrakesecure.net/en/ftp.php
SuSE squid-2.4.STABLE7-288.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/squid-2.4.STABLE7 -288.i586.rpm
Squid Web Proxy Cache 2.4 .STABLE6
Debian squid-cgi_2.4.6-2woody6_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2 woody6_alpha.deb
Debian squid-cgi_2.4.6-2woody6_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2 woody6_arm.deb
Debian squid-cgi_2.4.6-2woody6_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2 woody6_hppa.deb
Debian squid-cgi_2.4.6-2woody6_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2 woody6_i386.deb
Debian squid-cgi_2.4.6-2woody6_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2 woody6_ia64.deb
Debian squid-cgi_2.4.6-2woody6_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2 woody6_m68k.deb
Debian squid-cgi_2.4.6-2woody6_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2 woody6_mips.deb
Debian squid-cgi_2.4.6-2woody6_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2 woody6_mipsel.deb
Debian squid-cgi_2.4.6-2woody6_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2 woody6_powerpc.deb
Debian squid-cgi_2.4.6-2woody6_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2 woody6_s390.deb
Debian squid-cgi_2.4.6-2woody6_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2 woody6_sparc.deb
Debian squid_2.4.6-2woody6_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2wood y6_alpha.deb
Debian squid_2.4.6-2woody6_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2wood y6_arm.deb
Debian squid_2.4.6-2woody6_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2wood y6_hppa.deb
Debian squid_2.4.6-2woody6_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2wood y6_i386.deb
Debian squid_2.4.6-2woody6_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2wood y6_ia64.deb
Debian squid_2.4.6-2woody6_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2wood y6_m68k.deb
Debian squid_2.4.6-2woody6_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2wood y6_mips.deb
Debian squid_2.4.6-2woody6_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2wood y6_mipsel.deb
Debian squid_2.4.6-2woody6_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2wood y6_powerpc.deb
Debian squid_2.4.6-2woody6_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2wood y6_s390.deb
Debian squid_2.4.6-2woody6_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2wood y6_sparc.deb
Debian squidclient_2.4.6-2woody6_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6 -2woody6_alpha.deb
Debian squidclient_2.4.6-2woody6_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6 -2woody6_arm.deb
Debian squidclient_2.4.6-2woody6_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6 -2woody6_hppa.deb
Debian squidclient_2.4.6-2woody6_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6 -2woody6_i386.deb
Debian squidclient_2.4.6-2woody6_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6 -2woody6_ia64.deb
Debian squidclient_2.4.6-2woody6_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6 -2woody6_m68k.deb
Debian squidclient_2.4.6-2woody6_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6 -2woody6_mips.deb
Debian squidclient_2.4.6-2woody6_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6 -2woody6_mipsel.deb
Debian squidclient_2.4.6-2woody6_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6 -2woody6_powerpc.deb
Debian squidclient_2.4.6-2woody6_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6 -2woody6_s390.deb
Debian squidclient_2.4.6-2woody6_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6 -2woody6_sparc.deb
RedHat squid-2.4.STABLE7-0.73.3.legacy.i386.rpm
Red Hat Linux 7.3:
http://download.fedoralegacy.org/redhat/7.3/updates/i386/squid-2.4.STA BLE7-0.73.3.legacy.i386.rpm
Squid Web Proxy Cache 2.4 .STABLE2
Mandrake squid-2.4.STABLE7-1.3.M82mdk.i586.rpm
Mandrake Multi Network Firewall 8.2
http://www.mandrakesecure.net/en/ftp.php
Squid Web Proxy Cache 2.5 .STABLE4
Mandrake squid-2.5.STABLE4-1.100mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandrake squid-2.5.STABLE4-1.2.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php
Mandrake squid-2.5.STABLE4-1.2.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php
Mandrake squid-2.5.STABLE4-2.1.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php
Mandrake squid-2.5.STABLE4-2.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php
Mandrake squid-2.5.STABLE4-2.2.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php
Mandrake squid-2.5.STABLE4-2.2.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php
Mandrake squid-2.5.STABLE4-2.3.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php
Mandrake squid-2.5.STABLE4-2.3.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php
Mandrake squid-2.5.STABLE4-2.3.C30mdk.i586.rpm
Mandrake

参考网址

来源: US-CERT
名称: VU#625878
链接:http://www.kb.cert.org/vuls/id/625878

来源: REDHAT
名称: RHSA-2005:061
链接:http://www.redhat.com/support/errata/RHSA-2005-061.html

来源: REDHAT
名称: RHSA-2005:060
链接:http://www.redhat.com/support/errata/RHSA-2005-060.html

来源: SUSE
名称: SUSE-SA:2005:006
链接:http://www.novell.com/linux/security/advisories/2005_06_squid.html

来源: DEBIAN
名称: DSA-667
链接:http://www.debian.org/security/2005/dsa-667

来源: BUGTRAQ
名称: 20050207 [USN-77-1] Squid vulnerabilities
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=110780531820947&w=2

来源: CONECTIVA
名称: CLA-2005:931
链接:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000931

来源: www.squid-cache.org
链接:http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-response_splitting

来源: www.squid-cache.org
链接:http://www.squid-cache.org/Advisories/SQUID-2005_5.txt

来源: FEDORA
名称: FEDORA-2005-373
链接:http://www.redhat.com/archives/fedora-announce-list/2005-May/msg00025.html

来源: BID
名称: 12433
链接:http://www.securityfocus.com/bid/12433

来源: MANDRAKE
名称: MDKSA-2005:034
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2005:034

来源: FEDORA
名称: FLSA-2006:152809
链接:http://fedoranews.org/updates/FEDORA–.shtml

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享