积极预防 及时发现
快速响应 力保恢复
Squid是一个运行于Linux/Unix系统下的Web服务代理程序。Squid FTP代理程序在处...
发布时间:2002-03-11 信息来源:管理员

CNCVE编号:CNCVE-20020033 CVE编号:CAN-2002-0068 安全级别:高 漏洞中文描述: Squid是一个运行于Linux/Unix系统下的Web服务代理程序。Squid FTP代理程序在处理FTP URL时存在缓冲区溢出问题,远程攻击者可能利用这个漏洞对服务器程序实施拒绝服务攻击。通过发送一个特别构造的ftp:// URL给Squid服务器程序,可能导致服务器程序崩溃,需要手工重启才能恢复功能。这个漏洞也有可能导致在服务器上以Squid进程的身份执行任意指令。 漏洞英文描述: A buffer overflow exists in the Squid proxy server's FTP URL handling. If a user has the ability to use the Squid process to proxy FTP requests, it may be possible for the user make a malicious request. By sending a custom-crafted ftp:// URL through the squid proxy, it is possible to crash the server, requiring manual restart to resume normal operation. This problem may also allow the execution of code with the privileges of the Squid process. 漏洞参考: http://archives.neohapsis.com/archives/bugtraq/2002-02/0230.html http://www.squid-cache.org/Advisories/SQUID-2002_1.txt ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:12.squid.asc https://www.redhat.com/support/errata/RHSA-2002-029.htm 系统类型:其他 漏洞类型:输入有效性检查错误