CVE-2005-0175
CVSS5.0
发布时间 :2005-02-07 00:00:00
修订时间 :2016-10-17 23:08:08
NMCOPS    

[原文]Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache via an HTTP response splitting attack.


[CNNVD]Squid 畸形http 响应解析缓存攻击漏洞(CNNVD-200502-008)

        Squid是一个高效的Web缓存及代理程序,Squid最初是为Unix平台开发的,现在也被移植到Linux和大多数的Unix类系统中,最新的Squid可以运行在Windows平台下。
        Squid在处理畸形HTTP请求和应答时存在问题,远程攻击者可以利用这个漏洞在squid缓存中放置不安全或错误的内容。

- CVSS (基础分值)

CVSS分值: 5 [中等(MEDIUM)]
机密性影响: [--]
完整性影响: [--]
可用性影响: [--]
攻击复杂度: [--]
攻击向量: [--]
身份认证: [--]

- CPE (受影响的平台与产品)

cpe:/a:squid:squid:2.5_.stable1
cpe:/a:squid:squid:2.5_stable3
cpe:/a:squid:squid:2.5_stable4
cpe:/a:squid:squid:2.5_.stable5
cpe:/a:squid:squid:2.5_.stable6
cpe:/a:squid:squid:2.5_.stable3
cpe:/a:squid:squid:2.5_.stable4
cpe:/a:squid:squid:2.5_stable9
cpe:/a:squid:squid:2.5.stable2
cpe:/a:squid:squid:2.5.stable3
cpe:/a:squid:squid:2.5.stable1
cpe:/a:squid:squid:2.5.stable6
cpe:/a:squid:squid:2.5.stable7
cpe:/a:squid:squid:2.5.stable4
cpe:/a:squid:squid:2.5.stable5
cpe:/a:squid:squid:2.5.6

- OVAL (用于检测的技术细节)

oval:org.mitre.oval:def:11605Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache via an HTTP response splitting attack.
*OVAL详细的描述了检测该漏洞的方法,你可以从相关的OVAL定义中找到更多检测该漏洞的技术细节。

- 官方数据库链接

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0175
(官方数据源) MITRE
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2005-0175
(官方数据源) NVD
http://www.cnnvd.org.cn/vulnerability/show/cv_cnnvdid/CNNVD-200502-008
(官方数据源) CNNVD

- 其它链接及资源

http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000931
(VENDOR_ADVISORY)  CONECTIVA  CLA-2005:931
http://fedoranews.org/updates/FEDORA--.shtml
(UNKNOWN)  FEDORA  FLSA-2006:152809
http://marc.info/?l=bugtraq&m=110780531820947&w=2
(UNKNOWN)  BUGTRAQ  20050207 [USN-77-1] Squid vulnerabilities
http://www.debian.org/security/2005/dsa-667
(VENDOR_ADVISORY)  DEBIAN  DSA-667
http://www.kb.cert.org/vuls/id/625878
(VENDOR_ADVISORY)  CERT-VN  VU#625878
http://www.mandriva.com/security/advisories?name=MDKSA-2005:034
(UNKNOWN)  MANDRAKE  MDKSA-2005:034
http://www.novell.com/linux/security/advisories/2005_06_squid.html
(VENDOR_ADVISORY)  SUSE  SUSE-SA:2005:006
http://www.redhat.com/archives/fedora-announce-list/2005-May/msg00025.html
(UNKNOWN)  FEDORA  FEDORA-2005-373
http://www.redhat.com/support/errata/RHSA-2005-060.html
(VENDOR_ADVISORY)  REDHAT  RHSA-2005:060
http://www.redhat.com/support/errata/RHSA-2005-061.html
(VENDOR_ADVISORY)  REDHAT  RHSA-2005:061
http://www.securityfocus.com/bid/12433
(UNKNOWN)  BID  12433
http://www.squid-cache.org/Advisories/SQUID-2005_5.txt
(VENDOR_ADVISORY)  CONFIRM  http://www.squid-cache.org/Advisories/SQUID-2005_5.txt
http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-response_splitting
(VENDOR_ADVISORY)  CONFIRM  http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-response_splitting

- 漏洞信息

Squid 畸形http 响应解析缓存攻击漏洞
中危 输入验证
2005-02-07 00:00:00 2005-10-20 00:00:00
远程  
        Squid是一个高效的Web缓存及代理程序,Squid最初是为Unix平台开发的,现在也被移植到Linux和大多数的Unix类系统中,最新的Squid可以运行在Windows平台下。
        Squid在处理畸形HTTP请求和应答时存在问题,远程攻击者可以利用这个漏洞在squid缓存中放置不安全或错误的内容。

- 公告与补丁

        目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
        Squid Web Proxy Cache 2.4 .STABLE7
        Mandrake squid-2.4.STABLE7-1.2.M82mdk.i586.rpm
        http://www.mandrakesecure.net/en/ftp.php
        Mandrake squid-2.4.STABLE7-2.1.C21mdk.i586.rpm
        http://www.mandrakesecure.net/en/ftp.php
        Mandrake squid-2.4.STABLE7-2.1.C21mdk.x86_64.rpm
        http://www.mandrakesecure.net/en/ftp.php
        Mandrake squid-2.4.STABLE7-2.2.C21mdk.i586.rpm
        Mandrake Corporate Server 2.1
        http://www.mandrakesecure.net/en/ftp.php
        Mandrake squid-2.4.STABLE7-2.2.C21mdk.x86_64.rpm
        Mandrake Corporate Server 2.1/x86_64
        http://www.mandrakesecure.net/en/ftp.php
        Mandrake squid-2.4.STABLE7-2.3.C21mdk.i586.rpm
        Mandrake Corporate Server 2.1
        http://www.mandrakesecure.net/en/ftp.php
        Mandrake squid-2.4.STABLE7-2.3.C21mdk.x86_64.rpm
        Mandrake Corporate Server 2.1/x86_64
        http://www.mandrakesecure.net/en/ftp.php
        Mandrake squid-2.4.STABLE7-2.4.C21mdk.i586.rpm
        Mandrake Corporate Server 2.1
        http://www.mandrakesecure.net/en/ftp.php
        Mandrake squid-2.4.STABLE7-2.4.C21mdk.x86_64.rpm
        Mandrake Corporate Server 2.1/x86_64
        http://www.mandrakesecure.net/en/ftp.php
        Mandrake squid-2.4.STABLE7-2.5.C21mdk.i586.rpm
        Mandrake Corporate Server 2.1
        http://www.mandrakesecure.net/en/ftp.php
        Mandrake squid-2.4.STABLE7-2.5.C21mdk.x86_64.rpm
        Mandrake Corporate Server 2.1/x86_64
        http://www.mandrakesecure.net/en/ftp.php
        SuSE squid-2.4.STABLE7-288.i586.rpm
        ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/squid-2.4.STABLE7 -288.i586.rpm
        Squid Web Proxy Cache 2.4 .STABLE6
        Debian squid-cgi_2.4.6-2woody6_alpha.deb
        Debian GNU/Linux 3.0 alias woody
        http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2 woody6_alpha.deb
        Debian squid-cgi_2.4.6-2woody6_arm.deb
        Debian GNU/Linux 3.0 alias woody
        http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2 woody6_arm.deb
        Debian squid-cgi_2.4.6-2woody6_hppa.deb
        Debian GNU/Linux 3.0 alias woody
        http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2 woody6_hppa.deb
        Debian squid-cgi_2.4.6-2woody6_i386.deb
        Debian GNU/Linux 3.0 alias woody
        http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2 woody6_i386.deb
        Debian squid-cgi_2.4.6-2woody6_ia64.deb
        Debian GNU/Linux 3.0 alias woody
        http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2 woody6_ia64.deb
        Debian squid-cgi_2.4.6-2woody6_m68k.deb
        Debian GNU/Linux 3.0 alias woody
        http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2 woody6_m68k.deb
        Debian squid-cgi_2.4.6-2woody6_mips.deb
        Debian GNU/Linux 3.0 alias woody
        http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2 woody6_mips.deb
        Debian squid-cgi_2.4.6-2woody6_mipsel.deb
        Debian GNU/Linux 3.0 alias woody
        http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2 woody6_mipsel.deb
        Debian squid-cgi_2.4.6-2woody6_powerpc.deb
        Debian GNU/Linux 3.0 alias woody
        http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2 woody6_powerpc.deb
        Debian squid-cgi_2.4.6-2woody6_s390.deb
        Debian GNU/Linux 3.0 alias woody
        http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2 woody6_s390.deb
        Debian squid-cgi_2.4.6-2woody6_sparc.deb
        Debian GNU/Linux 3.0 alias woody
        http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2 woody6_sparc.deb
        Debian squid_2.4.6-2woody6_alpha.deb
        Debian GNU/Linux 3.0 alias woody
        http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2wood y6_alpha.deb
        Debian squid_2.4.6-2woody6_arm.deb
        Debian GNU/Linux 3.0 alias woody
        http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2wood y6_arm.deb
        Debian squid_2.4.6-2woody6_hppa.deb
        Debian GNU/Linux 3.0 alias woody
        http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2wood y6_hppa.deb
        Debian squid_2.4.6-2woody6_i386.deb
        Debian GNU/Linux 3.0 alias woody
        http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2wood y6_i386.deb
        Debian squid_2.4.6-2woody6_ia64.deb
        Debian GNU/Linux 3.0 alias woody
        http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2wood y6_ia64.deb
        Debian squid_2.4.6-2woody6_m68k.deb
        Debian GNU/Linux 3.0 alias woody
        http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2wood y6_m68k.deb
        Debian squid_2.4.6-2woody6_mips.deb
        Debian GNU/Linux 3.0 alias woody
        http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2wood y6_mips.deb
        Debian squid_2.4.6-2woody6_mipsel.deb
        Debian GNU/Linux 3.0 alias woody
        http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2wood y6_mipsel.deb
        Debian squid_2.4.6-2woody6_powerpc.deb
        Debian GNU/Linux 3.0 alias woody
        http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2wood y6_powerpc.deb
        Debian squid_2.4.6-2woody6_s390.deb
        Debian GNU/Linux 3.0 alias woody
        http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2wood y6_s390.deb
        Debian squid_2.4.6-2woody6_sparc.deb
        Debian GNU/Linux 3.0 alias woody
        http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2wood y6_sparc.deb
        Debian squidclient_2.4.6-2woody6_alpha.deb
        Debian GNU/Linux 3.0 alias woody
        http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6 -2woody6_alpha.deb
        Debian squidclient_2.4.6-2woody6_arm.deb
        Debian GNU/Linux 3.0 alias woody
        http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6 -2woody6_arm.deb
        Debian squidclient_2.4.6-2woody6_hppa.deb
        Debian GNU/Linux 3.0 alias woody
        http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6 -2woody6_hppa.deb
        Debian squidclient_2.4.6-2woody6_i386.deb
        Debian GNU/Linux 3.0 alias woody
        http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6 -2woody6_i386.deb
        Debian squidclient_2.4.6-2woody6_ia64.deb
        Debian GNU/Linux 3.0 alias woody
        http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6 -2woody6_ia64.deb
        Debian squidclient_2.4.6-2woody6_m68k.deb
        Debian GNU/Linux 3.0 alias woody
        http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6 -2woody6_m68k.deb
        Debian squidclient_2.4.6-2woody6_mips.deb
        Debian GNU/Linux 3.0 alias woody
        http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6 -2woody6_mips.deb
        Debian squidclient_2.4.6-2woody6_mipsel.deb
        Debian GNU/Linux 3.0 alias woody
        http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6 -2woody6_mipsel.deb
        Debian squidclient_2.4.6-2woody6_powerpc.deb
        Debian GNU/Linux 3.0 alias woody
        http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6 -2woody6_powerpc.deb
        Debian squidclient_2.4.6-2woody6_s390.deb
        Debian GNU/Linux 3.0 alias woody
        http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6 -2woody6_s390.deb
        Debian squidclient_2.4.6-2woody6_sparc.deb
        Debian GNU/Linux 3.0 alias woody
        http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6 -2woody6_sparc.deb
        RedHat squid-2.4.STABLE7-0.73.3.legacy.i386.rpm
        Red Hat Linux 7.3:
        http://download.fedoralegacy.org/redhat/7.3/updates/i386/squid-2.4.STA BLE7-0.73.3.legacy.i386.rpm
        Squid Web Proxy Cache 2.4 .STABLE2
        Mandrake squid-2.4.STABLE7-1.3.M82mdk.i586.rpm
        Mandrake Multi Network Firewall 8.2
        http://www.mandrakesecure.net/en/ftp.php
        Squid Web Proxy Cache 2.5 .STABLE4
        Mandrake squid-2.5.STABLE4-1.100mdk.i586.rpm
        http://www.mandrakesecure.net/en/ftp.php
        Mandrake squid-2.5.STABLE4-1.2.100mdk.amd64.rpm
        Mandrake Linux 10.0/AMD64
        http://www.mandrakesecure.net/en/ftp.php
        Mandrake squid-2.5.STABLE4-1.2.100mdk.i586.rpm
        Mandrake Linux 10.0
        http://www.mandrakesecure.net/en/ftp.php
        Mandrake squid-2.5.STABLE4-2.1.100mdk.amd64.rpm
        Mandrake Linux 10.0/AMD64
        http://www.mandrakesecure.net/en/ftp.php
        Mandrake squid-2.5.STABLE4-2.1.100mdk.i586.rpm
        Mandrake Linux 10.0
        http://www.mandrakesecure.net/en/ftp.php
        Mandrake squid-2.5.STABLE4-2.2.100mdk.amd64.rpm
        Mandrake Linux 10.0/AMD64
        http://www.mandrakesecure.net/en/ftp.php
        Mandrake squid-2.5.STABLE4-2.2.100mdk.i586.rpm
        Mandrake Linux 10.0
        http://www.mandrakesecure.net/en/ftp.php
        Mandrake squid-2.5.STABLE4-2.3.100mdk.amd64.rpm
        Mandrake Linux 10.0/AMD64
        http://www.mandrakesecure.net/en/ftp.php
        Mandrake squid-2.5.STABLE4-2.3.100mdk.i586.rpm
        Mandrake Linux 10.0
        http://www.mandrakesecure.net/en/ftp.php
        Mandrake squid-2.5.STABLE4-2.3.C30mdk.i586.rpm
        Mandrake

- 漏洞信息 (F36038)

Debian Linux Security Advisory 667-1 (PacketStormID:F36038)
2005-02-06 00:00:00
Debian  debian.org
advisory,vulnerability
linux,debian
CVE-2005-0173,CVE-2005-0175,CVE-2005-0194,CVE-2005-0211
[点击下载]

Debian Security Advisory 667-1 - Several vulnerabilities have been discovered in Squid, the internet object cache, the popular WWW proxy cache.

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- --------------------------------------------------------------------------
Debian Security Advisory DSA 667-1                     security@debian.org
http://www.debian.org/security/                             Martin Schulze
February 4th, 2005                      http://www.debian.org/security/faq
- --------------------------------------------------------------------------

Package        : squid
Vulnerability  : several
Problem-Type   : remote
Debian-specific: no
CVE IDs        : CAN-2005-0173 CAN-2005-0175 CAN-2005-0194 CAN-2005-0211

Several vulnerabilities have been discovered in Squid, the internet
object cache, the popular WWW proxy cache.  The Common Vulnerabilities
and Exposures project identifies the following vulnerabilities:

CAN-2005-0173

    LDAP is very forgiving about spaces in search filters and this
    could be abused to log in using several variants of the login
    name, possibly bypassing explicit access controls or confusing
    accounting.

CAN-2005-0175

    Cache pollution/poisening via HTTP response splitting has been
    discovered.

CAN-2005-0194

    The meaning of the access controls becomes somewhat confusing if
    any of the referenced ACLs (access control lists) is declared
    empty, without any members.

CAN-2005-0211

    The length argument of the WCCP recvfrom() call is larger than it
    should be.  An attacker may send a larger than normal WCCP packet
    that could overflow a buffer.

For the stable distribution (woody) these problems have been fixed in
version 2.4.6-2woody6.

For the unstable distribution (sid) these problems have been fixed in
version 2.5.7-7.

We recommend that you upgrade your squid package.


Upgrade Instructions
- --------------------

wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
        will update the internal database
apt-get upgrade
        will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian GNU/Linux 3.0 alias woody
- --------------------------------

  Source archives:

    http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody6.dsc
      Size/MD5 checksum:      612 f585baec3cc0548a0b6d3e21d185db50
    http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody6.diff.gz
      Size/MD5 checksum:   235426 85d38139f57a82f3c422421ad352e70e
    http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6.orig.tar.gz
      Size/MD5 checksum:  1081920 59ce2c58da189626d77e27b9702ca228

  Alpha architecture:

    http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody6_alpha.deb
      Size/MD5 checksum:   815424 ecbca01e45af0d55e94bcd6dc93a140a
    http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2woody6_alpha.deb
      Size/MD5 checksum:    75546 e3ad6d3c681293593ab8e0c3ed46e56d
    http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6-2woody6_alpha.deb
      Size/MD5 checksum:    60290 bd894e6b88b4155a4d79ab346ef0ecf0

  ARM architecture:

    http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody6_arm.deb
      Size/MD5 checksum:   725786 00174ebf650a7becff1a974766a8ef18
    http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2woody6_arm.deb
      Size/MD5 checksum:    73324 496ebaa76ff79e0b3df5032e9db249ee
    http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6-2woody6_arm.deb
      Size/MD5 checksum:    58634 b036414c28e9371324b2b2112e2195ef

  Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody6_i386.deb
      Size/MD5 checksum:   684246 5f932b6cd8e3fae41bee679b8f78ce9d
    http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2woody6_i386.deb
      Size/MD5 checksum:    73820 51b9d7d06722aa12086d5e321521c957
    http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6-2woody6_i386.deb
      Size/MD5 checksum:    58322 8fceca376dc96840d11e210f2796dcb4

  Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody6_ia64.deb
      Size/MD5 checksum:   953904 aeaee5d9ee53e39a3aa1e1b775d12142
    http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2woody6_ia64.deb
      Size/MD5 checksum:    79392 1430eda6e1c2c4b4b8b7fade39efbdc4
    http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6-2woody6_ia64.deb
      Size/MD5 checksum:    62960 8cebaa32f4f3f17eef2d731fc4c154b3

  HP Precision architecture:

    http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody6_hppa.deb
      Size/MD5 checksum:   779494 9341bc9e4b7c39806601a378aad51d56
    http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2woody6_hppa.deb
      Size/MD5 checksum:    74766 8479e2a71ae184650520cf3a139bc1ad
    http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6-2woody6_hppa.deb
      Size/MD5 checksum:    59772 bc6dff1697cb54f3c3baa9fbb21cd49b

  Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody6_m68k.deb
      Size/MD5 checksum:   666170 bfea1f097c0913615dd885cf6090ff90
    http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2woody6_m68k.deb
      Size/MD5 checksum:    72654 3db952c5d712e4e0a54db5215f2ae812
    http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6-2woody6_m68k.deb
      Size/MD5 checksum:    57868 c81e9618868ea0e82b0c2179067fe3eb

  Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody6_mips.deb
      Size/MD5 checksum:   765316 8a18eea8fa4f5a738cf2c9415233d172
    http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2woody6_mips.deb
      Size/MD5 checksum:    74292 5a6f6f6ac7dd721d9dba3478a5c478de
    http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6-2woody6_mips.deb
      Size/MD5 checksum:    58946 eae54358cc4adcc85d754fbd6ca29225

  Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody6_mipsel.deb
      Size/MD5 checksum:   765424 0490a5ec43851928800922afd54a2d5f
    http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2woody6_mipsel.deb
      Size/MD5 checksum:    74392 1093f566bac7bf08d1da720439234d80
    http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6-2woody6_mipsel.deb
      Size/MD5 checksum:    59036 7846b97c6c8661b1e07889fff408b250

  PowerPC architecture:

    http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody6_powerpc.deb
      Size/MD5 checksum:   722620 0c8c21ad09813e7565022c35f87dd29c
    http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2woody6_powerpc.deb
      Size/MD5 checksum:    73302 d86696f63adab59d1fadbd64702ca633
    http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6-2woody6_powerpc.deb
      Size/MD5 checksum:    58522 7d812f5b516060abcdb0eb977ea85a5e

  IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody6_s390.deb
      Size/MD5 checksum:   712166 809bb77631c098b4c1f548f7d4101f88
    http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2woody6_s390.deb
      Size/MD5 checksum:    73646 ff34ec95644ed86adfde338834bbe014
    http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6-2woody6_s390.deb
      Size/MD5 checksum:    59084 27e215b7b647ce8fbabd1108fc9dbec4

  Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody6_sparc.deb
      Size/MD5 checksum:   724716 da2925f0ab258d718872525a6a2f0a80
    http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2woody6_sparc.deb
      Size/MD5 checksum:    75932 5b46ca56b3274c5e4dbdab3556a85491
    http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6-2woody6_sparc.deb
      Size/MD5 checksum:    60956 7a2ec6fb96971c29edfabce83c0069ec


  These files will probably be moved into the stable distribution on
  its next update.

- ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)

iD8DBQFCA6RvW5ql+IAeqTIRArERAJ9RzG0Oko2BOd4TdCmy066szqDWygCfdWjV
R0Sv6Ly/9lV7nT/fQbPRyv8=
=LwDu
-----END PGP SIGNATURE-----

    

- 漏洞信息

13346
Squid HTTP Response Splitting Cache Poisoning
Loss of Integrity

- 漏洞描述

Unknown or Incomplete

- 时间线

2005-01-25 Unknow
Unknow Unknow

- 解决方案

Unknown or Incomplete

- 相关参考

- 漏洞作者

Unknown or Incomplete

- 漏洞信息

Squid Proxy Malformed HTTP Header Parsing Cache Poisoning Vulnerability
Input Validation Error 12433
Yes No
2005-02-02 12:00:00 2007-02-22 02:16:00
The individual or individuals responsible for the discovery of this issue are currently unknown; the vendor disclosed this issue.

- 受影响的程序版本

Squid Web Proxy Cache 2.5 .STABLE7
+ Conectiva Linux 10.0
+ Conectiva Linux 9.0
+ Gentoo Linux
+ Red Hat Fedora Core3
+ Red Hat Fedora Core2
Squid Web Proxy Cache 2.5 .STABLE6
+ Mandriva Linux Mandrake 10.1 x86_64
+ S.u.S.E. Linux Personal 9.2 x86_64
+ S.u.S.E. Linux Personal 9.2
+ Turbolinux Appliance Server 1.0 Workgroup Edition
+ Turbolinux Appliance Server 1.0 Hosting Edition
+ Turbolinux Appliance Server Hosting Edition 1.0
+ Turbolinux Appliance Server Workgroup Edition 1.0
+ Turbolinux Turbolinux Server 10.0
+ Turbolinux Turbolinux Server 8.0
+ Turbolinux Turbolinux Server 7.0
+ Turbolinux Turbolinux Workstation 8.0
+ Turbolinux Turbolinux Workstation 7.0
Squid Web Proxy Cache 2.5 .STABLE5
+ Conectiva Linux 10.0
+ Conectiva Linux 9.0
+ S.u.S.E. Linux Personal 9.1 x86_64
+ S.u.S.E. Linux Personal 9.1
+ Trustix Secure Linux 2.1
+ Trustix Secure Linux 2.0
+ Ubuntu Ubuntu Linux 4.1 ppc
+ Ubuntu Ubuntu Linux 4.1 ia64
+ Ubuntu Ubuntu Linux 4.1 ia32
Squid Web Proxy Cache 2.5 .STABLE4
+ MandrakeSoft Corporate Server 3.0
+ Mandriva Linux Mandrake 10.0 AMD64
+ Mandriva Linux Mandrake 10.0
+ OpenPKG OpenPKG 2.0
+ OpenPKG OpenPKG Current
Squid Web Proxy Cache 2.5 .STABLE3
+ Mandriva Linux Mandrake 9.2 amd64
+ Mandriva Linux Mandrake 9.2
+ OpenPKG OpenPKG 1.3
+ Red Hat Enterprise Linux AS 3
+ Red Hat Fedora Core1
+ RedHat Desktop 3.0
+ RedHat Enterprise Linux ES 3
+ RedHat Enterprise Linux WS 3
+ S.u.S.E. Linux Personal 9.0 x86_64
+ S.u.S.E. Linux Personal 9.0
Squid Web Proxy Cache 2.5 .STABLE1
+ Mandriva Linux Mandrake 9.1 ppc
+ Mandriva Linux Mandrake 9.1
+ S.u.S.E. Linux Personal 8.2
Squid Web Proxy Cache 2.4 .STABLE7
+ MandrakeSoft Corporate Server 2.1 x86_64
+ MandrakeSoft Corporate Server 2.1
+ MandrakeSoft Multi Network Firewall 2.0
+ Red Hat Enterprise Linux AS 2.1 IA64
+ Red Hat Enterprise Linux AS 2.1
+ RedHat Enterprise Linux ES 2.1 IA64
+ RedHat Enterprise Linux ES 2.1
+ RedHat Enterprise Linux WS 2.1 IA64
+ RedHat Enterprise Linux WS 2.1
+ RedHat Linux Advanced Work Station 2.1
Squid Web Proxy Cache 2.4 .STABLE6
+ Debian Linux 3.0 sparc
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 alpha
+ Debian Linux 3.0
Squid Web Proxy Cache 2.4 .STABLE2
Squid Web Proxy Cache 2.4
+ Debian Linux 3.0 sparc
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 alpha
+ Debian Linux 3.0
Squid Web Proxy Cache 2.3 .STABLE5
Squid Web Proxy Cache 2.3 .STABLE4
Squid Web Proxy Cache 2.1 PATCH2
Squid Web Proxy Cache 2.0 PATCH2
SGI ProPack 3.0
S.u.S.E. Linux Personal 9.2
S.u.S.E. Linux Personal 9.1
S.u.S.E. Linux Personal 9.0 x86_64
S.u.S.E. Linux Personal 9.0
S.u.S.E. Linux Personal 8.2
S.u.S.E. Linux 8.1
RedHat Linux 9.0 i386
RedHat Linux 7.3 i386
Red Hat Fedora Core2
Red Hat Fedora Core1
Astaro Security Linux 4.0 17
Astaro Security Linux 4.0 16
Astaro Security Linux 4.0 08
Astaro Security Linux 3.217
Astaro Security Linux 3.2 16
Astaro Security Linux 3.2 15
Astaro Security Linux 3.2 12
Astaro Security Linux 3.2 11
Astaro Security Linux 3.2 10
Astaro Security Linux 3.2 00
Astaro Security Linux 2.0 30
Astaro Security Linux 2.0 27
Astaro Security Linux 2.0 26
Astaro Security Linux 2.0 25
Astaro Security Linux 2.0 24
Astaro Security Linux 2.0 23
Astaro Security Linux 2.0 16

- 漏洞讨论

Squid Proxy is reported prone to a cache-poisoning vulnerability when processing malformed HTTP requests and responses. This issue results from insufficient sanitization of user-supplied data.

Squid versions 2.5 and earlier are reported prone to this issue.

- 漏洞利用

An exploit is not required.

- 解决方案

Please see the referenced vendor advisories for more information and fixes.


Squid Web Proxy Cache 2.4 .STABLE7

Squid Web Proxy Cache 2.4 .STABLE6

Squid Web Proxy Cache 2.4 .STABLE2

Squid Web Proxy Cache 2.5 .STABLE4

Squid Web Proxy Cache 2.5 .STABLE7

Squid Web Proxy Cache 2.5 .STABLE6

Squid Web Proxy Cache 2.5 .STABLE1

Squid Web Proxy Cache 2.5 .STABLE3

Squid Web Proxy Cache 2.5 .STABLE5

SGI ProPack 3.0

- 相关参考

 

 

关于SCAP中文社区

SCAP中文社区是国内第一个以SCAP为主题的中文开放社区。了解更多信息,请查阅[关于本站]

版权声明

CVE/CWE/OVAL均为MITRE公司的注册商标,它们的官方数据源均保存在MITRE公司的相关网站