Squid CONNECT/SSL Miss_Access DoS Vulnerability
BID:4201
Info
Squid CONNECT/SSL Miss_Access DoS Vulnerability
| Bugtraq ID: | 4201 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 23 2001 12:00AM |
| Updated: | Oct 23 2001 12:00AM |
| Credit: | This issue appears to have been discovered by the Squid development team. |
| Vulnerable: |
National Science Foundation Squid Web Proxy 2.4 STABLE2 National Science Foundation Squid Web Proxy 2.4 STABLE1 |
| Not Vulnerable: | |
Discussion
Squid CONNECT/SSL Miss_Access DoS Vulnerability
Squid Web Proxy Cache is a free, open source proxy server.
Under some circumstances Squid Web Proxy is prone to crashing. If a host is allowed by http_access but denied by miss_proxy, a condition occurs where Squid Web Proxy will crash if that host tries to make a connection.
If the circumstances for this vulnerability exist, it is possible for a remote attacker to exploit the condition.
The proxy server will need to be restarted to regain normal functionality.
Earlier versions may also be affected.
Squid Web Proxy Cache is a free, open source proxy server.
Under some circumstances Squid Web Proxy is prone to crashing. If a host is allowed by http_access but denied by miss_proxy, a condition occurs where Squid Web Proxy will crash if that host tries to make a connection.
If the circumstances for this vulnerability exist, it is possible for a remote attacker to exploit the condition.
The proxy server will need to be restarted to regain normal functionality.
Earlier versions may also be affected.
Exploit / POC
Squid CONNECT/SSL Miss_Access DoS Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Squid CONNECT/SSL Miss_Access DoS Vulnerability
Solution:
Upgrades are available.
National Science Foundation Squid Web Proxy 2.4 STABLE2
National Science Foundation Squid Web Proxy 2.4 STABLE1
Solution:
Upgrades are available.
National Science Foundation Squid Web Proxy 2.4 STABLE2
-
Conectiva squid-2.4.1-4U70_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/squid-2.4.1-4U70_2cl.i386 .rpm -
Conectiva squid-auth-2.4.1-4U70_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/squid-auth-2.4.1-4U70_2cl .i386.rpm -
Conectiva squid-doc-2.4.1-4U70_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/squid-doc-2.4.1-4U70_2cl. i386.rpm -
Conectiva squid-templates-2.4.1-4U70_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/squid-templates-2.4.1-4U7 0_2cl.i386.rpm -
National Science Foundation squid-2.4.STABLE4-src.tar.gz
http://www.squid-cache.org/Versions/v2/2.4/squid-2.4.STABLE4-src.tar.g z
National Science Foundation Squid Web Proxy 2.4 STABLE1
-
National Science Foundation squid-2.4.STABLE4-src.tar.gz
http://www.squid-cache.org/Versions/v2/2.4/squid-2.4.STABLE4-src.tar.g z