积极预防 及时发现
快速响应 力保恢复
Squid是一个运行于Linux/Unix系统下的Web服务代理程序。Squid代理程序的SNMP实...
发布时间:2002-03-11 信息来源:管理员

CNCVE编号:CNCVE-20020034 CVE编号:CAN-2002-0069 安全级别:高 漏洞中文描述: Squid是一个运行于Linux/Unix系统下的Web服务代理程序。Squid代理程序的SNMP实现上存在内存泄露问题,远程攻击者可能利用此问题对服务器程序实施拒绝服务攻击。远程攻击者可能通过不断提交畸形的SNMP消息给服务器,使服务器程序消耗完系统所有可用资源,如果没有对Squid进程设置资源限制则可能导致服务器性能的下降。如果要利用这个漏洞,服务器的SNMP端口必须开放,攻击者必须能够向那个端口发送数据,SNMP支持在Squid的默认安装中是关闭的。 漏洞英文描述: A memory leak exists in the Squid proxy server's SNMP implementation. It may be possible for remote attackers to cause the process to consume all allowable resources by repeatedly transmitting malformed SNMP messages. If resource limits have not been set on the Squid process, the performance of the entire system may be degraded. To exploit this vulnerability, the Squid SNMP interface must be enabled and the attacker must be able to send traffic to the SNMP port. SNMP support in Squid is disabled by default. 漏洞参考: http://archives.neohapsis.com/archives/bugtraq/2002-02/0230.html http://www.squid-cache.org/Advisories/SQUID-2002_1.txt ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:12.squid.asc https://www.redhat.com/support/errata/RHSA-2002-029.htm 系统类型: 其他 漏洞类型:异常处理错误