CERT-In Vulnerability Note
CIVN-2005-0111
Squid Proxy Client NTLM Authentication Denial Of Service Vulnerability
Original Issue Date:November 08, 2005
Severity Rating: HIGH
Systems Affected
Squid Web Proxy Cache Version 2.5 .STABLE9
Overview
Squid is a popular web proxy server used in Linux systems. A vulnerability has been reported in the squid proxy verson 2.5.STABLE9 may allow remote users to cause DDoS attack.
Description
It has been reported that the Squid version 2.5.STABLE9 and earlier are vulnerable to DDoS attack.
While performing NTLM authentication, squid does not properly validate certain requests, which allows remote attackers to cause a denial of service attack.
Solution
Apply the relevant patch available or upgradefrom vendor
http://www.squid-cache.org/Versions/v2/2.5/squid-
Vendor Information
Squid Web Proxy Cache
http://www.squid-cache.org/
Squid Web Proxy Advisory
http://www.squid-cache.org/bugs/show_bug.cgi?id=1391
References
Securityfocus
http://www.securityfocus.com/bid/14977/discuss
Secunia Advisory
http://secunia.com/advisories/16992
CVE Name
CAN-2005-2917
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|