Squid Proxy NTLM Authentication Buffer Overflow Vulnerability
BID:10500
Info
Squid Proxy NTLM Authentication Buffer Overflow Vulnerability
| Bugtraq ID: | 10500 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-0541 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 09 2004 12:00AM |
| Updated: | Nov 15 2007 12:40AM |
| Credit: | The discoverer of this issue wishes to remain anonymous. |
| Vulnerable: |
Squid Web Proxy Cache 2.5 .STABLE5 Squid Web Proxy Cache 2.5 .STABLE4 Squid Web Proxy Cache 2.5 .STABLE3 Squid Web Proxy Cache 2.5 .STABLE1 Squid Web Proxy Cache 2.4 .STABLE7 Squid Web Proxy Cache 2.4 Squid Web Proxy Cache 2.3 .STABLE5 Squid Web Proxy Cache 2.1 PATCH2 Squid Web Proxy Cache 2.0 PATCH2 SGI ProPack 3.0 Redhat Linux 9.0 i386 Redhat Linux 8.0 i686 Redhat Linux 8.0 i386 Redhat Linux 8.0 Redhat Linux 7.3 i386 Redhat Fedora Core2 Redhat Fedora Core1 Mandriva Linux Mandrake 7.2 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 |
| Not Vulnerable: | |
Discussion
Squid Proxy NTLM Authentication Buffer Overflow Vulnerability
Squid Web Proxy Cache is reportedly affected by a buffer-overflow vulnerability when processing NTLM authentication credentials. The application fails to properly validate buffer boundaries when copying user-supplied input.
This would allow an attacker to modify stack-based process memory to cause a denial-of-service condition and execute arbitrary code in the context of the vulnerable web proxy. This will most likely facilitate unauthorized access to the affected computer.
Squid Web Proxy Cache is reportedly affected by a buffer-overflow vulnerability when processing NTLM authentication credentials. The application fails to properly validate buffer boundaries when copying user-supplied input.
This would allow an attacker to modify stack-based process memory to cause a denial-of-service condition and execute arbitrary code in the context of the vulnerable web proxy. This will most likely facilitate unauthorized access to the affected computer.
Exploit / POC
Squid Proxy NTLM Authentication Buffer Overflow Vulnerability
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
An exploit is available for the Metasploit Framework:
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
An exploit is available for the Metasploit Framework:
Solution / Fix
Squid Proxy NTLM Authentication Buffer Overflow Vulnerability
Solution:
Please see the referenced advisories for more information and fixes.
Squid Web Proxy Cache 2.4
Squid Web Proxy Cache 2.5 .STABLE4
Squid Web Proxy Cache 2.5 .STABLE1
Squid Web Proxy Cache 2.5 .STABLE3
Squid Web Proxy Cache 2.5 .STABLE5
SGI ProPack 3.0
Solution:
Please see the referenced advisories for more information and fixes.
Squid Web Proxy Cache 2.4
-
SuSE squid-2.4.STABLE6-9.i386.patch.rpm
Intel i386 Platform
ftp://ftp.suse.com/pub/suse/i386/update/8.0/n2/squid-2.4.STABLE6-9.i38 6.patch.rpm
Squid Web Proxy Cache 2.5 .STABLE4
-
Mandrake squid-2.5.STABLE4-1.2.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake squid-2.5.STABLE4-1.2.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Squid libntlmssp.c.patch
http://www.squid-cache.org/~wessels/patch/libntlmssp.c.patch
Squid Web Proxy Cache 2.5 .STABLE1
-
Mandrake squid-2.5.STABLE1-7.2.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake squid-2.5.STABLE1-7.2.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
RedHat squid-2.5.STABLE1-9.10.legacy.i386.rpm
Red Hat Linux 9:
http://download.fedoralegacy.org/redhat/9/updates/i386/squid-2.5.STABL E1-9.10.legacy.i386.rpm -
Squid libntlmssp.c.patch
http://www.squid-cache.org/~wessels/patch/libntlmssp.c.patch -
SuSE squid-2.5.STABLE1-98.i586.patch.rpm
Intel i386 Platform
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/squid-2.5.STABLE1 -98.i586.patch.rpm -
SuSE squid-2.5.STABLE1-98.i586.rpm
Intel i386 Platform
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/squid-2.5.STABLE1 -98.i586.rpm
Squid Web Proxy Cache 2.5 .STABLE3
-
Fedora squid-2.5.STABLE3-2.fc1.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
Fedora squid-2.5.STABLE3-2.fc1.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
Fedora squid-debuginfo-2.5.STABLE3-2.fc1.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
Fedora squid-debuginfo-2.5.STABLE3-2.fc1.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
Mandrake squid-2.5.STABLE3-3.2.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake squid-2.5.STABLE3-3.2.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
RedHat squid-2.5.STABLE3-2.fc1.6.legacy.i386.rpm
Fedora Core 1:
http://download.fedoralegacy.org/fedora/1/updates/i386/squid-2.5.STABL E3-2.fc1.6.legacy.i386.rpm -
Squid libntlmssp.c.patch
http://www.squid-cache.org/~wessels/patch/libntlmssp.c.patch -
SuSE squid-2.5.STABLE3-110.i586.patch.rpm
Intel i386 Platform
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/squid-2.5.STABLE3 -110.i586.patch.rpm -
SuSE squid-2.5.STABLE3-110.x86_64.patch.rpm
Opteron x86_64 Platform
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/squid-2.5.STA BLE3-110.x86_64.patch.rpm -
SuSE squid-2.5.STABLE3-110.i586.rpm
Intel i386 Platform
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/squid-2.5.STABLE3 -110.i586.rpm -
SuSE squid-2.5.STABLE3-110.x86_64.rpm
Opteron x86_64 Platform
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/squid-2.5.STA BLE3-110.x86_64.rpm
Squid Web Proxy Cache 2.5 .STABLE5
-
Conectiva squid-2.5.5-25761U90_7cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/squid-2.5.5-25761U90_7cl.i3 86.rpm -
Conectiva squid-2.5.5-63116U10_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/squid-2.5.5-63116U10_4cl.i 386.rpm -
Conectiva squid-auth-2.5.5-25761U90_7cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/squid-auth-2.5.5-25761U90_7 cl.i386.rpm -
Conectiva squid-auth-2.5.5-63116U10_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/squid-auth-2.5.5-63116U10_ 4cl.i386.rpm -
Conectiva squid-extra-templates-2.5.5-25761U90_7cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/squid-extra-templates-2.5.5 -25761U90_7cl.i386.rpm -
Conectiva squid-extra-templates-2.5.5-63116U10_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/squid-extra-templates-2.5. 5-63116U10_4cl.i386.rpm -
Fedora squid-2.5.STABLE5-4.fc2.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora squid-2.5.STABLE5-4.fc2.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora squid-debuginfo-2.5.STABLE5-4.fc2.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora squid-debuginfo-2.5.STABLE5-4.fc2.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
RedHat squid-2.5.STABLE9-1.FC2.4.legacy.i386.rpm
Fedora Core 2:
http://download.fedoralegacy.org/fedora/2/updates/i386/squid-2.5.STABL E9-1.FC2.4.legacy.i386.rpm -
Squid libntlmssp.c.patch
http://www.squid-cache.org/~wessels/patch/libntlmssp.c.patch -
SuSE squid-2.5.STABLE5-42.9.i586.patch.rpm
Intel i386 Platform
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/squid-2.5.STABLE5 -42.9.i586.patch.rpm -
SuSE squid-2.5.STABLE5-42.9.x86_64.patch.rpm
Opteron x86_64 Platform
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/squid-2.5.STA BLE5-42.9.x86_64.patch.rpm -
SuSE squid-2.5.STABLE5-42.9.i586.rpm
Intel i386 Platform
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/squid-2.5.STABLE5 -42.9.i586.rpm -
SuSE squid-2.5.STABLE5-42.9.x86_64.rpm
Opteron x86_64 Platform
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/squid-2.5.STA BLE5-42.9.x86_64.rpm -
tinysofa squid-2.5.STABLE5-6ts.i586.rpm
http://http.tinysofa.org/pub/tinysofa/updates/server-1.0/rpms/squid-2. 5.STABLE5-6ts.i586.rpm -
Trustix squid-2.5.STABLE5-0.2tr.i586.rpm
http://http.trustix.org/pub/trustix/updates/2.0/rpms/squid-2.5.STABLE5 -0.2tr.i586.rpm -
Trustix squid-2.5.STABLE5-5tr.i586.rpm
http://http.trustix.org/pub/trustix/updates/2.1/rpms/squid-2.5.STABLE5 -5tr.i586.rpm
SGI ProPack 3.0
-
SGI patch10083.tar.gz
ftp://patches.sgi.com/support/free/security/patches/ProPack/3/patch100 83.tar.gz
References
Squid Proxy NTLM Authentication Buffer Overflow Vulnerability
References:
References:
- Metasploit Framework Exploits (Metasploit)
- RHSA-2004:242-06 - Updated squid package fixes security vulnerability (RedHat)
- Squid NTLM Authentication exploit (CORE Security)
- Squid Web Proxy Cache Homepage (Squid)
- Squid Web Proxy Cache NTLM Authentication Helper Buffer Overflow Vulnerability (iDEFENSE)