Gentoo Archives: gentoo-announce

From: Thierry Carrez <koon@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××.com, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200409-04 ] Squid: Denial of service when using NTLM authentication
Date: Thu, 02 Sep 2004 20:30:16
Message-Id: 41378267.2030502@gentoo.org
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
5 Gentoo Linux Security Advisory GLSA 200409-04
6 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
7 http://security.gentoo.org/
8 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
9
10 Severity: Normal
11 Title: Squid: Denial of service when using NTLM authentication
12 Date: September 02, 2004
13 Bugs: #61280
14 ID: 200409-04
15
16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
17
18 Synopsis
19 ========
20
21 Squid is vulnerable to a denial of service attack which could crash its
22 NTLM helpers.
23
24 Background
25 ==========
26
27 Squid is a full-featured Web Proxy Cache designed to run on Unix
28 systems. It supports proxying and caching of HTTP, FTP, and other URLs,
29 as well as SSL support, cache hierarchies, transparent caching, access
30 control lists and many other features.
31
32 Affected packages
33 =================
34
35 -------------------------------------------------------------------
36 Package / Vulnerable / Unaffected
37 -------------------------------------------------------------------
38 1 www-proxy/squid <= 2.5.6-r1 >= 2.5.6-r2
39 < 2.5
40
41 Description
42 ===========
43
44 Squid 2.5.x versions contain a bug in the functions ntlm_fetch_string()
45 and ntlm_get_string() which lack checking the int32_t offset "o" for
46 negative values.
47
48 Impact
49 ======
50
51 A remote attacker could cause a denial of service situation by sending
52 certain malformed NTLMSSP packets if NTLM authentication is enabled.
53
54 Workaround
55 ==========
56
57 Disable NTLM authentication by removing any "auth_param ntlm program
58 ..." directives from squid.conf or use ntlm_auth from Samba-3.x.
59
60 Resolution
61 ==========
62
63 All Squid users should upgrade to the latest stable version:
64
65 # emerge sync
66
67 # emerge -pv ">=net-www/squid-2.5.6-r2"
68 # emerge ">=net-www/squid-2.5.6-r2"
69
70 References
71 ==========
72
73 [ 1 ] Squid-2.5 Patches
74
75 http://www1.uk.squid-cache.org/squid/Versions/v2/2.5/bugs/#squid-2.5.STABLE6-ntlm_fetch_string
76
77 Availability
78 ============
79
80 This GLSA and any updates to it are available for viewing at
81 the Gentoo Security Website:
82
83 http://security.gentoo.org/glsa/glsa-200409-04.xml
84
85 Concerns?
86 =========
87
88 Security is a primary focus of Gentoo Linux and ensuring the
89 confidentiality and security of our users machines is of utmost
90 importance to us. Any security concerns should be addressed to
91 security@g.o or alternatively, you may file a bug at
92 http://bugs.gentoo.org.
93
94 License
95 =======
96
97 Copyright 2004 Gentoo Foundation, Inc; referenced text
98 belongs to its owner(s).
99
100 The contents of this document are licensed under the
101 Creative Commons - Attribution / Share Alike license.
102
103 http://creativecommons.org/licenses/by-sa/1.0
104
105 -----BEGIN PGP SIGNATURE-----
106 Version: GnuPG v1.2.4 (GNU/Linux)
107 Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org
108
109 iD8DBQFBN4JnvcL1obalX08RAmzBAJ0TjVsiwBafbVANOnWhnUtozgjvPACaA7kU
110 3/zvWQwNNg0LQhlq9sjBRZY=
111 =JVl6
112 -----END PGP SIGNATURE-----