Vulnerabilities > CVE-2002-0069 - Denial of Service vulnerability in Squid Cache SNMP
Attack vector
NETWORK Attack complexity
HIGH Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
PARTIAL Summary
Memory leak in SNMP in Squid 2.4 STABLE3 and earlier allows remote attackers to cause a denial of service.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 | |
OS | 10 |
Nessus
NASL family | Mandriva Local Security Checks |
NASL id | MANDRAKE_MDKSA-2002-016.NASL |
description | Three security issues were found in the 2.x versions of the Squid proxy server up to and including 2.4.STABLE3. The first is a memory leak in the optional SNMP interface to Squid which could allow a malicious user who can send packets to the Squid SNMP port to possibly perform a Denial of Service attack on ther server if the SNMP interface is enabled. The next is a buffer overflow in the implementation of ftp:// URLs where allowed users could possibly perform a DoS on the server, and may be able to trigger remote execution of code (which the authors have not yet confirmed). The final issue is with the HTCP interface which cannot be properly disabled from squid.conf; HTCP is enabled by default on Mandrake Linux systems. Update : The squid updates for all versions other than Mandrake Linux were incorrectly built with LDAP authentication which introduced a dependency on OpenLDAP. These new packages do not use LDAP authentication. The Single Network Firewall 7.2 package previously released did not use LDAP authentication, however rebuilding the source RPM package required LDAP to be installed. Single Network Firewall 7.2 users do not need to upgrade to these packages to have a properly function squid. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 13924 |
published | 2004-07-31 |
reporter | This script is Copyright (C) 2004-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/13924 |
title | Mandrake Linux Security Advisory : squid (MDKSA-2002:016-1) |
code |
|
Redhat
advisories |
|
References
- ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:12.squid.asc
- http://archives.neohapsis.com/archives/linux/caldera/2002-q1/0014.html
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000464
- http://marc.info/?l=bugtraq&m=101431040422095&w=2
- http://marc.info/?l=bugtraq&m=101443252627021&w=2
- http://www.iss.net/security_center/static/8260.php
- http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-016.php
- http://www.redhat.com/support/errata/RHSA-2002-029.html
- http://www.securityfocus.com/bid/4146
- http://www.squid-cache.org/Versions/v2/2.4/bugs/