Squid Proxy NTLM Authentication Denial Of Service Vulnerability
BID:11098
Info
Squid Proxy NTLM Authentication Denial Of Service Vulnerability
| Bugtraq ID: | 11098 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-0832 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 02 2004 12:00AM |
| Updated: | Dec 20 2006 08:53PM |
| Credit: | Marco Ortisi <[email protected]> disclosed this vulnerability to the vendor. |
| Vulnerable: |
Ubuntu Ubuntu Linux 4.1 ppc Ubuntu Ubuntu Linux 4.1 ia64 Ubuntu Ubuntu Linux 4.1 ia32 Trustix Secure Linux 2.1 Trustix Secure Linux 2.0 Trustix Secure Enterprise Linux 2.0 Squid Web Proxy Cache 3.0 PRE3 Squid Web Proxy Cache 3.0 PRE2 Squid Web Proxy Cache 3.0 PRE1 Squid Web Proxy Cache 2.5 .STABLE6 Squid Web Proxy Cache 2.5 .STABLE5 Squid Web Proxy Cache 2.5 .STABLE4 Squid Web Proxy Cache 2.5 .STABLE3 Squid Web Proxy Cache 2.5 .STABLE1 Squid Web Proxy Cache 2.4 .STABLE7 Squid Web Proxy Cache 2.4 Squid Web Proxy Cache 2.3 .STABLE5 Squid Web Proxy Cache 2.1 PATCH2 Squid Web Proxy Cache 2.0 PATCH2 Redhat Linux 9.0 i386 Redhat Linux 7.3 i386 Redhat Fedora Core2 Redhat Fedora Core1 Mandriva Linux Mandrake 10.0 AMD64 Mandriva Linux Mandrake 10.0 Mandriva Linux Mandrake 9.2 amd64 Mandriva Linux Mandrake 9.2 Gentoo Linux 1.4 |
| Not Vulnerable: | |
Discussion
Squid Proxy NTLM Authentication Denial Of Service Vulnerability
Squid is reported to be susceptible to a denial of service vulnerability in its NTLM authentication module.
This vulnerability presents itself when attacker supplied input data is passed to the affected NTLM module without proper sanitization.
This vulnerability allows an attacker to crash the NTLM helper application. Squid will respawn new helper applications, but with a sustained, repeating attack, it is likely that proxy authentication depending on the NTLM helper application would fail. Failure of NTLM authentication would result in the Squid application denying access to legitimate users of the proxy.
Squid versions 2.x and 3.x are all reported to be vulnerable to this issue. A patch is available from the vendor.
Squid is reported to be susceptible to a denial of service vulnerability in its NTLM authentication module.
This vulnerability presents itself when attacker supplied input data is passed to the affected NTLM module without proper sanitization.
This vulnerability allows an attacker to crash the NTLM helper application. Squid will respawn new helper applications, but with a sustained, repeating attack, it is likely that proxy authentication depending on the NTLM helper application would fail. Failure of NTLM authentication would result in the Squid application denying access to legitimate users of the proxy.
Squid versions 2.x and 3.x are all reported to be vulnerable to this issue. A patch is available from the vendor.
Exploit / POC
Squid Proxy NTLM Authentication Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Squid Proxy NTLM Authentication Denial Of Service Vulnerability
Solution:
Please see the referenced vendor advisories for more information and fixes.
Squid Web Proxy Cache 2.5 .STABLE6
Squid Web Proxy Cache 2.5 .STABLE4
Squid Web Proxy Cache 2.5 .STABLE1
Squid Web Proxy Cache 2.5 .STABLE3
Squid Web Proxy Cache 2.5 .STABLE5
Solution:
Please see the referenced vendor advisories for more information and fixes.
Squid Web Proxy Cache 2.5 .STABLE6
-
Squid squid-2.5.STABLE6-ntlm_fetch_string.patch
http://www1.uk.squid-cache.org/squid/Versions/v2/2.5/bugs/squid-2.5.ST ABLE6-ntlm_fetch_string.patch
Squid Web Proxy Cache 2.5 .STABLE4
-
Mandrake squid-2.5.STABLE4-2.1.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake squid-2.5.STABLE4-2.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php
Squid Web Proxy Cache 2.5 .STABLE1
-
RedHat squid-2.5.STABLE1-9.10.legacy.i386.rpm
Red Hat Linux 9:
http://download.fedoralegacy.org/redhat/9/updates/i386/squid-2.5.STABL E1-9.10.legacy.i386.rpm
Squid Web Proxy Cache 2.5 .STABLE3
-
Mandrake squid-2.5.STABLE3-3.3.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake squid-2.5.STABLE3-3.3.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
RedHat squid-2.5.STABLE3-2.fc1.6.legacy.i386.rpm
Fedora Core 1:
http://download.fedoralegacy.org/fedora/1/updates/i386/squid-2.5.STABL E3-2.fc1.6.legacy.i386.rpm
Squid Web Proxy Cache 2.5 .STABLE5
-
Conectiva squid-2.5.5-25761U90_7cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/squid-2.5.5-25761U90_7cl.i3 86.rpm -
Conectiva squid-2.5.5-63116U10_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/squid-2.5.5-63116U10_4cl.i 386.rpm -
Conectiva squid-auth-2.5.5-25761U90_7cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/squid-auth-2.5.5-25761U90_7 cl.i386.rpm -
Conectiva squid-auth-2.5.5-63116U10_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/squid-auth-2.5.5-63116U10_ 4cl.i386.rpm -
Conectiva squid-extra-templates-2.5.5-25761U90_7cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/squid-extra-templates-2.5.5 -25761U90_7cl.i386.rpm -
Conectiva squid-extra-templates-2.5.5-63116U10_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/squid-extra-templates-2.5. 5-63116U10_4cl.i386.rpm -
RedHat squid-2.5.STABLE9-1.FC2.4.legacy.i386.rpm
Fedora Core 2:
http://download.fedoralegacy.org/fedora/2/updates/i386/squid-2.5.STABL E9-1.FC2.4.legacy.i386.rpm -
Trustix squid-2.5.STABLE5-0.3tr.i586.rpm
Trustix Secure Linux 2.0, 2.1 & Enterprise Server 2
ftp://ftp.trustix.org/pub/trustix/updates/ -
Ubuntu squid-cgi_2.5.5-6ubuntu0.2_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/s/squid/squid-cgi_2.5. 5-6ubuntu0.2_amd64.deb -
Ubuntu squid-cgi_2.5.5-6ubuntu0.2_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/s/squid/squid-cgi_2.5. 5-6ubuntu0.2_i386.deb -
Ubuntu squid-cgi_2.5.5-6ubuntu0.2_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/s/squid/squid-cgi_2.5. 5-6ubuntu0.2_powerpc.deb -
Ubuntu squid-common_2.5.5-6ubuntu0.2_all.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/s/squid/squid-common_2.5.5 -6ubuntu0.2_all.deb -
Ubuntu squid_2.5.5-6ubuntu0.2_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/s/squid/squid_2.5.5-6ubunt u0.2_amd64.deb -
Ubuntu squid_2.5.5-6ubuntu0.2_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/s/squid/squid_2.5.5-6ubunt u0.2_i386.deb -
Ubuntu squid_2.5.5-6ubuntu0.2_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/s/squid/squid_2.5.5-6ubunt u0.2_powerpc.deb -
Ubuntu squidclient_2.5.5-6ubuntu0.2_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/s/squid/squidclient_2. 5.5-6ubuntu0.2_amd64.deb -
Ubuntu squidclient_2.5.5-6ubuntu0.2_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/s/squid/squidclient_2. 5.5-6ubuntu0.2_i386.deb -
Ubuntu squidclient_2.5.5-6ubuntu0.2_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/s/squid/squidclient_2. 5.5-6ubuntu0.2_powerpc.deb
References
Squid Proxy NTLM Authentication Denial Of Service Vulnerability
References:
References: