Squid FTP Server Response Denial Of Service Vulnerability
BID:15157
Info
Squid FTP Server Response Denial Of Service Vulnerability
| Bugtraq ID: | 15157 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-3258 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 20 2005 12:00AM |
| Updated: | Apr 04 2006 05:08PM |
| Credit: | "Martin Stransky" <[email protected]> has reported this vulnerability. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 8 SuSE Linux Openexchange Server SuSE Linux Enterprise Server 9 SuSE Linux Desktop 1.0 Squid Web Proxy Cache 2.5 .STABLE9 Squid Web Proxy Cache 2.5 .STABLE6 Squid Web Proxy Cache 2.5 .STABLE5 Squid Web Proxy Cache 2.5 .STABLE4 Squid Web Proxy Cache 2.5 .STABLE3 Squid Web Proxy Cache 2.5 .STABLE10 Squid Web Proxy Cache 2.5 .STABLE10 Squid Web Proxy Cache 2.4 .STABLE7 Squid Web Proxy Cache 2.4 .STABLE4 SCO Unixware 7.1.4 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Professional 8.2 S.u.S.E. Linux Professional 8.2 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 Redhat Fedora Core4 Redhat Fedora Core3 Mandriva Linux Mandrake 2006.0 x86_64 Mandriva Linux Mandrake 2006.0 Mandriva Linux Mandrake 10.2 x86_64 Mandriva Linux Mandrake 10.2 Mandriva Linux Mandrake 10.1 x86_64 Mandriva Linux Mandrake 10.1 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 IPCop IPCop 1.4.9 IPCop IPCop 1.4.8 IPCop IPCop 1.4.6 IPCop IPCop 1.4.5 IPCop IPCop 1.4.4 IPCop IPCop 1.4.2 IPCop IPCop 1.4.1 |
| Not Vulnerable: |
IPCop IPCop 1.4.10 |
Discussion
Squid FTP Server Response Denial Of Service Vulnerability
Squid is prone to a remote denial-of-service vulnerability. This is due to a flaw in the way that Squid communicates with FTP servers.
This issue has been reported in Squid version 2.5 and prior.
Squid is prone to a remote denial-of-service vulnerability. This is due to a flaw in the way that Squid communicates with FTP servers.
This issue has been reported in Squid version 2.5 and prior.
Exploit / POC
Squid FTP Server Response Denial Of Service Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
Squid FTP Server Response Denial Of Service Vulnerability
Solution:
Please see the referenced advisories for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected]
IPCop IPCop 1.4.1
IPCop IPCop 1.4.2
IPCop IPCop 1.4.4
IPCop IPCop 1.4.5
IPCop IPCop 1.4.6
IPCop IPCop 1.4.8
IPCop IPCop 1.4.9
Squid Web Proxy Cache 2.5 .STABLE5
Solution:
Please see the referenced advisories for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected]
IPCop IPCop 1.4.1
-
IPCop ipcop-sources-1.4.10.tgz
http://prdownloads.sourceforge.net/ipcop/ipcop-sources-1.4.10.tgz?down load
IPCop IPCop 1.4.2
-
IPCop ipcop-sources-1.4.10.tgz
http://prdownloads.sourceforge.net/ipcop/ipcop-sources-1.4.10.tgz?down load
IPCop IPCop 1.4.4
-
IPCop ipcop-sources-1.4.10.tgz
http://prdownloads.sourceforge.net/ipcop/ipcop-sources-1.4.10.tgz?down load
IPCop IPCop 1.4.5
-
IPCop ipcop-sources-1.4.10.tgz
http://prdownloads.sourceforge.net/ipcop/ipcop-sources-1.4.10.tgz?down load
IPCop IPCop 1.4.6
-
IPCop ipcop-sources-1.4.10.tgz
http://prdownloads.sourceforge.net/ipcop/ipcop-sources-1.4.10.tgz?down load
IPCop IPCop 1.4.8
-
IPCop ipcop-sources-1.4.10.tgz
http://prdownloads.sourceforge.net/ipcop/ipcop-sources-1.4.10.tgz?down load
IPCop IPCop 1.4.9
-
IPCop ipcop-sources-1.4.10.tgz
http://prdownloads.sourceforge.net/ipcop/ipcop-sources-1.4.10.tgz?down load
Squid Web Proxy Cache 2.5 .STABLE5
-
Conectiva squid-2.5.5-77559U10_13cl.i386.rpm
Version: 10.0
ftp://atualizacoes.conectiva.com.br/10/RPMS/squid-2.5.5-77559U10_13cl. i386.rpm -
Conectiva squid-auth-2.5.5-77559U10_13cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/squid-auth-2.5.5-77559U10_ 13cl.i386.rpm -
Conectiva squid-auth-2.5.5-77559U10_13cl.i386.rpm
Version: 10.0
ftp://atualizacoes.conectiva.com.br/10/RPMS/squid-auth-2.5.5-77559U10_ 13cl.i386.rpm -
Conectiva squid-extra-templates-2.5.5-77559U10_13cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/squid-extra-templates-2.5. 5-77559U10_13cl.i386.rpm -
Conectiva squid-extra-templates-2.5.5-77559U10_13cl.i386.rpm
Version: 10.0
ftp://atualizacoes.conectiva.com.br/10/RPMS/squid-extra-templates-2.5. 5-77559U10_13cl.i386.rpm -
Conectiva squid-2.5.5-77559U10_13cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/squid-2.5.5-77559U10_13cl. i386.rpm
References
Squid FTP Server Response Denial Of Service Vulnerability
References:
References:
- Fedora Homepage (RedHat)
- IPCop 1.4.10 Release Notes (IPCop)
- IPCop Home Page (IPCop)
- Squid Web Proxy Cache Homepage (Squid)