SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |    Help    |   

SecurityTracker
Archives


Welcome to SecurityTracker!
 
Click to Sign Up
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com

Sign Up!





Category:  Application (Generic)  >  Squid Vendors:  Squid-cache.org
(Fedora Issues Fix for FC2) Squid ntlm_check_auth() Buffer Overflow Lets Remote Users Execute Arbitrary Code
SecurityTracker Alert ID:  1010459
SecurityTracker URL:  http://securitytracker.com/id?1010459
CVE Reference:  CAN-2004-0541   (Links to External Site)
Date:  Jun 10 2004
Impact:  Execution of arbitrary code via network, User access via network
Fix Available:  Yes   Vendor Confirmed:  Yes  
Version(s): 3.*-PRE, 2.5.*
Description:  iDEFENSE reported a buffer overflow vulnerability in Squid in the processing of NTLM authentication messages. A remote user can execute arbitrary code on the target system.

It is reported that if the proxy is configured to use the NTLM authentication helper, a remote user can send a specially crafted password to trigger a buffer overflow in 'helpers/ntlm_auth/SMB/libntlmssp.c' in the ntlm_check_auth() function.

The vendor was reportedly notified on May 20, 2004.

Impact:  A remote user can execute arbitrary code on the target system.
Solution:  Fedora has released a fix, available at:

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

b735863f8f52314d1ff9981c85ea56b2 SRPMS/squid-2.5.STABLE5-4.fc2.src.rpm
4d80ef2db40a68a7ba2ecffdec9d3372 i386/squid-2.5.STABLE5-4.fc2.i386.rpm
779417acbbfe0e022bc1525d9faae339 i386/debug/squid-debuginfo-2.5.STABLE5-4.fc2.i386.rpm
c8c1bc2cd95f892ce602e3e38e9e7823 x86_64/squid-2.5.STABLE5-4.fc2.x86_64.rpm
fcb5484591641424a956b23c97614963 x86_64/debug/squid-debuginfo-2.5.STABLE5-4.fc2.x86_64.rpm

Vendor URL:  www.squid-cache.org/ (Links to External Site)
Cause:  Boundary error
Underlying OS:  Linux (Red Hat Fedora)
Underlying OS Comments:  Fedora Core 2
Reported By:  Jay Fenlason <fenlason@redhat.com>
Message History:   This archive entry is a follow-up to the message listed below.
Jun 8 2004 Squid ntlm_check_auth() Buffer Overflow Lets Remote Users Execute Arbitrary Code



 Source Message Contents

Date:  Wed, 9 Jun 2004 11:23:12 -0400
From:  Jay Fenlason <fenlason@redhat.com>
Subject:  [SECURITY] Fedora Core 2 Update: squid-2.5.STABLE5-4.fc2

 

---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2004-164
2004-06-09
---------------------------------------------------------------------

Product     : Fedora Core 2
Name        : squid
Version     : 2.5.STABLE5                      
Release     : 4.fc2                  
Summary     : The Squid proxy caching server.
Description :
Squid is a high-performance proxy caching server for Web clients,
supporting FTP, gopher, and HTTP data objects. Unlike traditional
caching software, Squid handles all requests in a single,
non-blocking, I/O-driven process. Squid keeps meta data and especially
hot objects cached in RAM, caches DNS lookups, supports non-blocking
DNS lookups, and implements negative caching of failed requests.

Squid consists of a main server program squid, a Domain Name System
lookup program (dnsserver), a program for retrieving FTP data
(ftpget), and some management and client tools.

---------------------------------------------------------------------

* Mon Jun 07 2004 Jay Fenlason <fenlason@redhat.com> 7:2.5.STABLE3-4.fc2

- Backport security fix for ntlm auth helper (CAN-2004-0541).

* Thu Apr 08 2004 Jay Fenlason <fenlason@redhat.com> 7:2.5.STABLE5-3

- Fix the -pipe patch to have the correct name of the winbind pipe.


---------------------------------------------------------------------
This update can be downloaded from:
  http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

b735863f8f52314d1ff9981c85ea56b2  SRPMS/squid-2.5.STABLE5-4.fc2.src.rpm
4d80ef2db40a68a7ba2ecffdec9d3372  i386/squid-2.5.STABLE5-4.fc2.i386.rpm
779417acbbfe0e022bc1525d9faae339  i386/debug/squid-debuginfo-2.5.STABLE5-4.fc2.i386.rpm
c8c1bc2cd95f892ce602e3e38e9e7823  x86_64/squid-2.5.STABLE5-4.fc2.x86_64.rpm
fcb5484591641424a956b23c97614963  x86_64/debug/squid-debuginfo-2.5.STABLE5-4.fc2.x86_64.rpm

This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.  
---------------------------------------------------------------------


--
fedora-announce-list mailing list
fedora-announce-list@redhat.com
http://www.redhat.com/mailman/listinfo/fedora-announce-list

 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us   |    Help

Copyright 2004, SecurityGlobal.net LLC