Debians sikkerhedsbulletin

DSA-576-1 squid -- flere sårbarheder

Rapporteret den:
29. okt 2004
Berørte pakker:
squid
Sårbar:
Ja
Referencer i sikkerhedsdatabaser:
I Debians fejlsporingssystem: Fejl 133131.
I Mitres CVE-ordbog: CVE-1999-0710, CVE-2004-0918.
Yderligere oplysninger:

Flere sikkerhedssårbarheder er opdaget i Squid, et mellemlagerprogram til Internet-filer og et populært WWW-proxy-mellemlager. Projektet Common Vulnerabilities and Exposures har fundet frem til følgende problemer:

  • CVE-1999-0710

    Det er muligt at omgå adgangslister og scanne vilkårlige værtsmaskiner og porte i netværket via cachemgr.cgi, der installeres som standard. Denne opdatering slår denne mulighed fra og introducerer en opsætningsfil (/etc/squid/cachemgr.conf) til at holde kontrol med denne funktionalitet.

  • CAN-2004-0918

    Funktionen asn_parse_header (asn1.c) i SNMP-modulet til Squid gør det muligt for fjernangribere at forårsage et lammelsesangreb via visse SNMP-pakker med negative længdefelter, der medfører en hukommelsesallokeringsfejl.

I den stabile distribution (woody) er disse problemer rettet i version 2.4.6-2woody4.

I den ustabile distribution (sid) er disse problemer rettet i version 2.5.7-1.

Vi anbefaler at du opgraderer din squid-pakke.

Rettet i:

Debian GNU/Linux 3.0 (woody)

Kildekode:
http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody4.dsc
http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody4.diff.gz
http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6.orig.tar.gz
Alpha:
http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody4_alpha.deb
http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2woody4_alpha.deb
http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6-2woody4_alpha.deb
ARM:
http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody4_arm.deb
http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2woody4_arm.deb
http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6-2woody4_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody4_i386.deb
http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2woody4_i386.deb
http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6-2woody4_i386.deb
Intel IA-64:
http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody4_ia64.deb
http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2woody4_ia64.deb
http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6-2woody4_ia64.deb
HPPA:
http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody4_hppa.deb
http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2woody4_hppa.deb
http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6-2woody4_hppa.deb
Motorola 680x0:
http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody4_m68k.deb
http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2woody4_m68k.deb
http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6-2woody4_m68k.deb
Big endian MIPS:
http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody4_mips.deb
http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2woody4_mips.deb
http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6-2woody4_mips.deb
Little endian MIPS:
http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody4_mipsel.deb
http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2woody4_mipsel.deb
http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6-2woody4_mipsel.deb
PowerPC:
http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody4_powerpc.deb
http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2woody4_powerpc.deb
http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6-2woody4_powerpc.deb
IBM S/390:
http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody4_s390.deb
http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2woody4_s390.deb
http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6-2woody4_s390.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/s/squid/squid_2.4.6-2woody4_sparc.deb
http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.4.6-2woody4_sparc.deb
http://security.debian.org/pool/updates/main/s/squid/squidclient_2.4.6-2woody4_sparc.deb

MD5-kontrolsummer for de listede filer findes i den originale sikkerhedsbulletin.