漏洞信息详情
Squid FTP服务器响应拒绝服务漏洞
漏洞简介
Squid(全称Squid Cache)是一套代理服务器和Web缓存服务器软件。该软件提供缓存万维网、过滤流量、代理上网等功能。
Squid 2.5 STABLE11及之前版本的ftp.c 中的rfc1738_do_escape函数允许远程FTP服务器借助特定的\"odd\" 响应,引起拒绝服务(分段故障)。
漏洞公告
目前厂商已经发布了升级补丁以修复此安全问题,补丁获取链接:
IPCop IPCop 1.4.1
IPCop ipcop-sources-1.4.10.tgz
http://prdownloads.sourceforge.net/ipcop/ipcop-sources-1.4.10.tgz?download
IPCop IPCop 1.4.2
IPCop ipcop-sources-1.4.10.tgz
http://prdownloads.sourceforge.net/ipcop/ipcop-sources-1.4.10.tgz?download
IPCop IPCop 1.4.4
IPCop ipcop-sources-1.4.10.tgz
http://prdownloads.sourceforge.net/ipcop/ipcop-sources-1.4.10.tgz?download
IPCop IPCop 1.4.5
IPCop ipcop-sources-1.4.10.tgz
http://prdownloads.sourceforge.net/ipcop/ipcop-sources-1.4.10.tgz?download
IPCop IPCop 1.4.6
IPCop ipcop-sources-1.4.10.tgz
http://prdownloads.sourceforge.net/ipcop/ipcop-sources-1.4.10.tgz?download
IPCop IPCop 1.4.8
IPCop ipcop-sources-1.4.10.tgz
http://prdownloads.sourceforge.net/ipcop/ipcop-sources-1.4.10.tgz?download
IPCop IPCop 1.4.9
IPCop ipcop-sources-1.4.10.tgz
http://prdownloads.sourceforge.net/ipcop/ipcop-sources-1.4.10.tgz?download
Squid Web Proxy Cache 2.5 .STABLE5
Conectiva squid-2.5.5-77559U10_13cl.i386.rpm
Version: 10.0
ftp://atualizacoes.conectiva.com.br/10/RPMS/squid-2.5.5-77559U10_13cl.i386.rpm
Conectiva squid-auth-2.5.5-77559U10_13cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/squid-auth-2.5.5-77559U10_13cl.i386.rpm
Conectiva squid-auth-2.5.5-77559U10_13cl.i386.rpm
Version: 10.0
ftp://atualizacoes.conectiva.com.br/10/RPMS/squid-auth-2.5.5-77559U10_13cl.i386.rpm
Conectiva squid-extra-templates-2.5.5-77559U10_13cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/squid-extra-templates-2.5.5-77559U10_13cl.i386.rpm
Conectiva squid-extra-templates-2.5.5-77559U10_13cl.i386.rpm
Version: 10.0
ftp://atualizacoes.conectiva.com.br/10/RPMS/squid-extra-templates-2.5.5-77559U10_13cl.i386.rpm
Conectiva squid-2.5.5-77559U10_13cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/squid-2.5.5-77559U10_13cl.i386.rpm
参考网址
来源: www.squid-cache.org
链接:http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE11-rfc1738_do_escape
来源: SUSE
名称: SUSE-SR:2005:027
链接:http://www.novell.com/linux/security/advisories/2005_27_sr.html
来源: SECTRACK
名称: 1015085
链接:http://www.frsirt.com/english/advisories/2005/2151
来源: SECTRACK
名称: 1015085
链接:http://securitytracker.com/id?1015085
来源: SECUNIA
名称: 17645
链接:http://secunia.com/advisories/17645
来源: SECUNIA
名称: 17626
链接:http://secunia.com/advisories/17626
来源: SECUNIA
名称: 17513
链接:http://secunia.com/advisories/17513
来源: SECUNIA
名称: 17407
链接:http://secunia.com/advisories/17407
来源: SECUNIA
名称: 17338
链接:http://secunia.com/advisories/17338
来源: SECUNIA
名称: 17287
链接:http://secunia.com/advisories/17287
来源: SECUNIA
名称: 17271
链接:http://secunia.com/advisories/17271
受影响实体
- Squid Squid 2.0.Patch1<!--2000-1-1-->
- Squid Squid 2.0.Patch2<!--2000-1-1-->
- Squid Squid 2.0.Pre1<!--2000-1-1-->
- Squid Squid 2.0.Release<!--2000-1-1-->
- Squid Squid 2.1.Patch1<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...