Executive Summary
Summary | |
---|---|
Title | Squid vulnerabilities |
Informations | |||
---|---|---|---|
Name | USN-414-1 | First vendor Publication | 2007-01-24 |
Vendor | Ubuntu | Last vendor Modification | 2007-01-24 |
Severity (Vendor) | N/A | Revision | N/A |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:N/I:N/A:P) | |||
---|---|---|---|
Cvss Base Score | 5 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 6.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: Ubuntu 6.10: In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: David Duncan Ross Palmer and Henrik Nordstrom discovered that squid incorrectly handled special characters in FTP URLs. Remote users with access to squid could crash the server leading to a denial of service. (CVE-2007-0247) Erick Dantas Rotole and Henrik Nordstrom discovered that squid could end up in an endless loop when exhausted of available external ACL helpers. Remote users with access to squid could cause CPU starvation, possibly leading to a denial of service. This does not affect a default Ubuntu installation, since external ACL helpers must be configured and used. (CVE-2007-0248) |
Original Source
Url : http://www.ubuntu.com/usn/USN-414-1 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-399 | Resource Management Errors |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 6 |
OpenVAS Exploits
Date | Description |
---|---|
2009-10-10 | Name : SLES9: Security update for squid File : nvt/sles9p5021105.nasl |
2009-04-09 | Name : Mandriva Update for squid MDKSA-2007:026 (squid) File : nvt/gb_mandriva_MDKSA_2007_026.nasl |
2009-03-23 | Name : Ubuntu Update for squid vulnerabilities USN-414-1 File : nvt/gb_ubuntu_USN_414_1.nasl |
2009-02-27 | Name : Fedora Update for squid FEDORA-2007-092 File : nvt/gb_fedora_2007_092_squid_fc5.nasl |
2009-01-28 | Name : SuSE Update for squid SUSE-SA:2007:012 File : nvt/gb_suse_2007_012.nasl |
2008-09-24 | Name : Gentoo Security Advisory GLSA 200701-22 (squid) File : nvt/glsa_200701_22.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
39839 | Squid squid/src/ftp.c Crafted FTP Directory Listing DoS |
32823 | Squid aclMatchExternal Function external_acl Queue Overload DoS |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Squid proxy FTP denial of service attempt RuleID : 10135 - Revision : 11 - Type : SERVER-OTHER |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2009-09-24 | Name : The remote SuSE 9 host is missing a security-related patch. File : suse9_11402.nasl - Type : ACT_GATHER_INFO |
2007-12-13 | Name : The remote SuSE 10 host is missing a security-related patch. File : suse_squid-2502.nasl - Type : ACT_GATHER_INFO |
2007-11-10 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-414-1.nasl - Type : ACT_GATHER_INFO |
2007-10-17 | Name : The remote openSUSE host is missing a security update. File : suse_squid-2504.nasl - Type : ACT_GATHER_INFO |
2007-03-20 | Name : The remote proxy server is affected by multiple denial of service vulnerabili... File : squid_cdos.nasl - Type : ACT_GATHER_INFO |
2007-02-18 | Name : The remote Mandrake Linux host is missing one or more security updates. File : mandrake_MDKSA-2007-026.nasl - Type : ACT_GATHER_INFO |
2007-02-18 | Name : The remote host is missing a vendor-supplied security patch File : suse_SA_2007_012.nasl - Type : ACT_GATHER_INFO |
2007-01-26 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-200701-22.nasl - Type : ACT_GATHER_INFO |
2007-01-18 | Name : The remote Fedora Core host is missing a security update. File : fedora_2007-092.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 12:04:07 |
|