CVE-2005-0211
CVSS7.5
发布时间 :2005-05-02 00:00:00
修订时间 :2016-11-07 17:29:11
NMCOPS    

[原文]Buffer overflow in wccp.c in Squid 2.5 before 2.5.STABLE7 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long WCCP packet, which is processed by a recvfrom function call that uses an incorrect length parameter.


[CNNVD]Squid Proxy WCCP recvfrom()远程缓冲区溢出漏洞(CNNVD-200505-026)

        Squid是一个高效的Web缓存及代理程序,Squid最初是为Unix平台开发的,现在也被移植到Linux和大多数的Unix类系统中,最新的Squid可以运行在Windows平台下。
        Squid在处理畸形WCCP包时存在问题,远程攻击者可以利用这个漏洞进行缓冲区溢出攻击,可能以进程权限执行任意指令。
        问题存在于WCCP-Web缓存通信协议,此为一个基于UDP的协议,由于WCCP recvfrom()调用对长度参数缺少充分检查,攻击者一个超大WCCP数据包可发生缓冲区溢出,精心构建提交数据可能以进程权限执行任意指令。
        

- CVSS (基础分值)

CVSS分值: 7.5 [严重(HIGH)]
机密性影响: [--]
完整性影响: [--]
可用性影响: [--]
攻击复杂度: [--]
攻击向量: [--]
身份认证: [--]

- CWE (弱点类目)

CWE-119 [内存缓冲区边界内操作的限制不恰当]

- CPE (受影响的平台与产品)

cpe:/a:squid:squid:2.5.stable1
cpe:/o:debian:debian_linux:3.0Debian Debian Linux 3.0
cpe:/a:squid:squid:2.5.stable6
cpe:/a:squid:squid:2.5.stable5
cpe:/a:squid:squid:2.5.stable4
cpe:/a:squid:squid:2.5.stable3
cpe:/a:squid:squid:2.5.stable2

- OVAL (用于检测的技术细节)

oval:org.mitre.oval:def:9573Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache via an HTTP response splitting attack.
*OVAL详细的描述了检测该漏洞的方法,你可以从相关的OVAL定义中找到更多检测该漏洞的技术细节。

- 官方数据库链接

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0211
(官方数据源) MITRE
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2005-0211
(官方数据源) NVD
http://www.cnnvd.org.cn/vulnerability/show/cv_cnnvdid/CNNVD-200505-026
(官方数据源) CNNVD

- 其它链接及资源

http://marc.info/?l=bugtraq&m=110780531820947&w=2
(VENDOR_ADVISORY)  BUGTRAQ  20050207 [USN-77-1] Squid vulnerabilities
http://securitytracker.com/id?1013045
(VENDOR_ADVISORY)  SECTRACK  1013045
http://www.debian.org/security/2005/dsa-667
(VENDOR_ADVISORY)  DEBIAN  DSA-667
http://www.kb.cert.org/vuls/id/886006
(VENDOR_ADVISORY)  CERT-VN  VU#886006
http://www.securityfocus.com/bid/12432
(VENDOR_ADVISORY)  BID  12432
http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-wccp_buffer_overflow
(VENDOR_ADVISORY)  CONFIRM  http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-wccp_buffer_overflow
http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-wccp_buffer_overflow.patch
(PATCH)  CONFIRM  http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-wccp_buffer_overflow.patch

- 漏洞信息

Squid Proxy WCCP recvfrom()远程缓冲区溢出漏洞
高危 缓冲区溢出
2005-05-02 00:00:00 2005-10-20 00:00:00
远程  
        Squid是一个高效的Web缓存及代理程序,Squid最初是为Unix平台开发的,现在也被移植到Linux和大多数的Unix类系统中,最新的Squid可以运行在Windows平台下。
        Squid在处理畸形WCCP包时存在问题,远程攻击者可以利用这个漏洞进行缓冲区溢出攻击,可能以进程权限执行任意指令。
        问题存在于WCCP-Web缓存通信协议,此为一个基于UDP的协议,由于WCCP recvfrom()调用对长度参数缺少充分检查,攻击者一个超大WCCP数据包可发生缓冲区溢出,精心构建提交数据可能以进程权限执行任意指令。
        

- 公告与补丁

        目前厂商已经发布了升级补丁以修复此安全问题,补丁获取链接:
        http://www.debian.org/security/2005/dsa-667

- 漏洞信息 (F36038)

Debian Linux Security Advisory 667-1 (PacketStormID:F36038)
2005-02-06 00:00:00
Debian  debian.org
advisory,vulnerability
linux,debian
CVE-2005-0173,CVE-2005-0175,CVE-2005-0194,CVE-2005-0211
[点击下载]

Debian Security Advisory 667-1 - Several vulnerabilities have been discovered in Squid, the internet object cache, the popular WWW proxy cache.

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- --------------------------------------------------------------------------
Debian Security Advisory DSA 667-1                     security@debian.org
http://www.debian.org/security/                             Martin Schulze
February 4th, 2005                      http://www.debian.org/security/faq
- --------------------------------------------------------------------------

Package        : squid
Vulnerability  : several
Problem-Type   : remote
Debian-specific: no
CVE IDs        : CAN-2005-0173 CAN-2005-0175 CAN-2005-0194 CAN-2005-0211

Several vulnerabilities have been discovered in Squid, the internet
object cache, the popular WWW proxy cache.  The Common Vulnerabilities
and Exposures project identifies the following vulnerabilities:

CAN-2005-0173

    LDAP is very forgiving about spaces in search filters and this
    could be abused to log in using several variants of the login
    name, possibly bypassing explicit access controls or confusing
    accounting.

CAN-2005-0175

    Cache pollution/poisening via HTTP response splitting has been
    discovered.

CAN-2005-0194

    The meaning of the access controls becomes somewhat confusing if
    any of the referenced ACLs (access control lists) is declared
    empty, without any members.

CAN-2005-0211

    The length argument of the WCCP recvfrom() call is larger than it
    should be.  An attacker may send a larger than normal WCCP packet
    that could overflow a buffer.

For the stable distribution (woody) these problems have been fixed in
version 2.4.6-2woody6.

For the unstable distribution (sid) these problems have been fixed in
version 2.5.7-7.

We recommend that you upgrade your squid package.


Upgrade Instructions
- --------------------

wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
        will update the internal database
apt-get upgrade
        will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian GNU/Linux 3.0 alias woody
- --------------------------------

  Source archives:

    http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody6.dsc
      Size/MD5 checksum:      612 f585baec3cc0548a0b6d3e21d185db50
    http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody6.diff.gz
      Size/MD5 checksum:   235426 85d38139f57a82f3c422421ad352e70e
    http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6.orig.tar.gz
      Size/MD5 checksum:  1081920 59ce2c58da189626d77e27b9702ca228

  Alpha architecture:

    http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody6_alpha.deb
      Size/MD5 checksum:   815424 ecbca01e45af0d55e94bcd6dc93a140a
    http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2woody6_alpha.deb
      Size/MD5 checksum:    75546 e3ad6d3c681293593ab8e0c3ed46e56d
    http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6-2woody6_alpha.deb
      Size/MD5 checksum:    60290 bd894e6b88b4155a4d79ab346ef0ecf0

  ARM architecture:

    http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody6_arm.deb
      Size/MD5 checksum:   725786 00174ebf650a7becff1a974766a8ef18
    http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2woody6_arm.deb
      Size/MD5 checksum:    73324 496ebaa76ff79e0b3df5032e9db249ee
    http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6-2woody6_arm.deb
      Size/MD5 checksum:    58634 b036414c28e9371324b2b2112e2195ef

  Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody6_i386.deb
      Size/MD5 checksum:   684246 5f932b6cd8e3fae41bee679b8f78ce9d
    http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2woody6_i386.deb
      Size/MD5 checksum:    73820 51b9d7d06722aa12086d5e321521c957
    http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6-2woody6_i386.deb
      Size/MD5 checksum:    58322 8fceca376dc96840d11e210f2796dcb4

  Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody6_ia64.deb
      Size/MD5 checksum:   953904 aeaee5d9ee53e39a3aa1e1b775d12142
    http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2woody6_ia64.deb
      Size/MD5 checksum:    79392 1430eda6e1c2c4b4b8b7fade39efbdc4
    http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6-2woody6_ia64.deb
      Size/MD5 checksum:    62960 8cebaa32f4f3f17eef2d731fc4c154b3

  HP Precision architecture:

    http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody6_hppa.deb
      Size/MD5 checksum:   779494 9341bc9e4b7c39806601a378aad51d56
    http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2woody6_hppa.deb
      Size/MD5 checksum:    74766 8479e2a71ae184650520cf3a139bc1ad
    http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6-2woody6_hppa.deb
      Size/MD5 checksum:    59772 bc6dff1697cb54f3c3baa9fbb21cd49b

  Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody6_m68k.deb
      Size/MD5 checksum:   666170 bfea1f097c0913615dd885cf6090ff90
    http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2woody6_m68k.deb
      Size/MD5 checksum:    72654 3db952c5d712e4e0a54db5215f2ae812
    http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6-2woody6_m68k.deb
      Size/MD5 checksum:    57868 c81e9618868ea0e82b0c2179067fe3eb

  Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody6_mips.deb
      Size/MD5 checksum:   765316 8a18eea8fa4f5a738cf2c9415233d172
    http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2woody6_mips.deb
      Size/MD5 checksum:    74292 5a6f6f6ac7dd721d9dba3478a5c478de
    http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6-2woody6_mips.deb
      Size/MD5 checksum:    58946 eae54358cc4adcc85d754fbd6ca29225

  Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody6_mipsel.deb
      Size/MD5 checksum:   765424 0490a5ec43851928800922afd54a2d5f
    http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2woody6_mipsel.deb
      Size/MD5 checksum:    74392 1093f566bac7bf08d1da720439234d80
    http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6-2woody6_mipsel.deb
      Size/MD5 checksum:    59036 7846b97c6c8661b1e07889fff408b250

  PowerPC architecture:

    http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody6_powerpc.deb
      Size/MD5 checksum:   722620 0c8c21ad09813e7565022c35f87dd29c
    http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2woody6_powerpc.deb
      Size/MD5 checksum:    73302 d86696f63adab59d1fadbd64702ca633
    http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6-2woody6_powerpc.deb
      Size/MD5 checksum:    58522 7d812f5b516060abcdb0eb977ea85a5e

  IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody6_s390.deb
      Size/MD5 checksum:   712166 809bb77631c098b4c1f548f7d4101f88
    http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2woody6_s390.deb
      Size/MD5 checksum:    73646 ff34ec95644ed86adfde338834bbe014
    http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6-2woody6_s390.deb
      Size/MD5 checksum:    59084 27e215b7b647ce8fbabd1108fc9dbec4

  Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody6_sparc.deb
      Size/MD5 checksum:   724716 da2925f0ab258d718872525a6a2f0a80
    http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2woody6_sparc.deb
      Size/MD5 checksum:    75932 5b46ca56b3274c5e4dbdab3556a85491
    http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6-2woody6_sparc.deb
      Size/MD5 checksum:    60956 7a2ec6fb96971c29edfabce83c0069ec


  These files will probably be moved into the stable distribution on
  its next update.

- ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)

iD8DBQFCA6RvW5ql+IAeqTIRArERAJ9RzG0Oko2BOd4TdCmy066szqDWygCfdWjV
R0Sv6Ly/9lV7nT/fQbPRyv8=
=LwDu
-----END PGP SIGNATURE-----

    

- 漏洞信息

13319
Squid WCCP recvfrom() Function Overflow
Input Manipulation
Loss of Integrity

- 漏洞描述

Unknown or Incomplete

- 时间线

2005-01-18 Unknow
Unknow Unknow

- 解决方案

Unknown or Incomplete

- 相关参考

- 漏洞作者

Unknown or Incomplete

- 漏洞信息

Squid Proxy WCCP recvfrom() Buffer Overflow Vulnerability
Boundary Condition Error 12432
Yes No
2005-02-02 12:00:00 2007-02-21 08:46:00
Discovered by FSC Internet Corporation.

- 受影响的程序版本

Squid Web Proxy Cache 2.5 .STABLE7
+ Conectiva Linux 10.0
+ Conectiva Linux 9.0
+ Gentoo Linux
+ Red Hat Fedora Core3
+ Red Hat Fedora Core2
Squid Web Proxy Cache 2.5 .STABLE6
+ Mandriva Linux Mandrake 10.1 x86_64
+ S.u.S.E. Linux Personal 9.2 x86_64
+ S.u.S.E. Linux Personal 9.2
+ Turbolinux Appliance Server 1.0 Workgroup Edition
+ Turbolinux Appliance Server 1.0 Hosting Edition
+ Turbolinux Appliance Server Hosting Edition 1.0
+ Turbolinux Appliance Server Workgroup Edition 1.0
+ Turbolinux Turbolinux Server 10.0
+ Turbolinux Turbolinux Server 8.0
+ Turbolinux Turbolinux Server 7.0
+ Turbolinux Turbolinux Workstation 8.0
+ Turbolinux Turbolinux Workstation 7.0
Squid Web Proxy Cache 2.5 .STABLE5
+ Conectiva Linux 10.0
+ Conectiva Linux 9.0
+ S.u.S.E. Linux Personal 9.1 x86_64
+ S.u.S.E. Linux Personal 9.1
+ Trustix Secure Linux 2.1
+ Trustix Secure Linux 2.0
+ Ubuntu Ubuntu Linux 4.1 ppc
+ Ubuntu Ubuntu Linux 4.1 ia64
+ Ubuntu Ubuntu Linux 4.1 ia32
Squid Web Proxy Cache 2.5 .STABLE4
+ MandrakeSoft Corporate Server 3.0
+ Mandriva Linux Mandrake 10.0 AMD64
+ Mandriva Linux Mandrake 10.0
+ OpenPKG OpenPKG 2.0
+ OpenPKG OpenPKG Current
Squid Web Proxy Cache 2.5 .STABLE3
+ Mandriva Linux Mandrake 9.2 amd64
+ Mandriva Linux Mandrake 9.2
+ OpenPKG OpenPKG 1.3
+ Red Hat Enterprise Linux AS 3
+ Red Hat Fedora Core1
+ RedHat Desktop 3.0
+ RedHat Enterprise Linux ES 3
+ RedHat Enterprise Linux WS 3
+ S.u.S.E. Linux Personal 9.0 x86_64
+ S.u.S.E. Linux Personal 9.0
Squid Web Proxy Cache 2.5 .STABLE1
+ Mandriva Linux Mandrake 9.1 ppc
+ Mandriva Linux Mandrake 9.1
+ S.u.S.E. Linux Personal 8.2
Squid Web Proxy Cache 2.4 .STABLE7
+ MandrakeSoft Corporate Server 2.1 x86_64
+ MandrakeSoft Corporate Server 2.1
+ MandrakeSoft Multi Network Firewall 2.0
+ Red Hat Enterprise Linux AS 2.1 IA64
+ Red Hat Enterprise Linux AS 2.1
+ RedHat Enterprise Linux ES 2.1 IA64
+ RedHat Enterprise Linux ES 2.1
+ RedHat Enterprise Linux WS 2.1 IA64
+ RedHat Enterprise Linux WS 2.1
+ RedHat Linux Advanced Work Station 2.1
Squid Web Proxy Cache 2.4 .STABLE6
+ Debian Linux 3.0 sparc
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 alpha
+ Debian Linux 3.0
Squid Web Proxy Cache 2.4 .STABLE2
Squid Web Proxy Cache 2.4
+ Debian Linux 3.0 sparc
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 alpha
+ Debian Linux 3.0
Squid Web Proxy Cache 2.3 .STABLE5
Squid Web Proxy Cache 2.3 .STABLE4
Squid Web Proxy Cache 2.1 PATCH2
Squid Web Proxy Cache 2.0 PATCH2
SGI ProPack 3.0
S.u.S.E. Linux Personal 9.2
S.u.S.E. Linux Personal 9.1
S.u.S.E. Linux Personal 9.0 x86_64
S.u.S.E. Linux Personal 9.0
S.u.S.E. Linux Personal 8.2
S.u.S.E. Linux 8.1
S.u.S.E. Linux 8.0 i386
S.u.S.E. Linux 8.0
RedHat Linux 9.0 i386
RedHat Linux 7.3 i386
Red Hat Fedora Core2
Red Hat Fedora Core1
Astaro Security Linux 4.0 16
Astaro Security Linux 4.0 08
Astaro Security Linux 3.217
Astaro Security Linux 3.2 16
Astaro Security Linux 3.2 15
Astaro Security Linux 3.2 12
Astaro Security Linux 3.2 11
Astaro Security Linux 3.2 10
Astaro Security Linux 3.2 00
Astaro Security Linux 2.0 30
Astaro Security Linux 2.0 27
Astaro Security Linux 2.0 26
Astaro Security Linux 2.0 25
Astaro Security Linux 2.0 24
Astaro Security Linux 2.0 23
Astaro Security Linux 2.0 16

- 漏洞讨论

The Squid proxy server is vulnerable to a remotely exploitable buffer-overflow vulnerability. The vulnerability resides in Squid's implementation of WCCP (web cache communication protocol), a UDP-based web cache management protocol. The condition is triggered when the server reads a packet that is larger than the size of the buffer allocated to store it. This can occur because 'recvfrom()' is passed an incorrect value for its 'len' argument.

- 漏洞利用

Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: vuldb@securityfocus.com <mailto:vuldb@securityfocus.com>.

- 解决方案

Please see the referenced vendor advisories for more information and fixes.


Squid Web Proxy Cache 2.4 .STABLE7

Squid Web Proxy Cache 2.4 .STABLE6

Squid Web Proxy Cache 2.4 .STABLE2

Squid Web Proxy Cache 2.5 .STABLE4

Squid Web Proxy Cache 2.5 .STABLE7

Squid Web Proxy Cache 2.5 .STABLE6

Squid Web Proxy Cache 2.5 .STABLE1

Squid Web Proxy Cache 2.5 .STABLE3

Squid Web Proxy Cache 2.5 .STABLE5

SGI ProPack 3.0

- 相关参考

 

 

关于SCAP中文社区

SCAP中文社区是国内第一个以SCAP为主题的中文开放社区。了解更多信息,请查阅[关于本站]

版权声明

CVE/CWE/OVAL均为MITRE公司的注册商标,它们的官方数据源均保存在MITRE公司的相关网站