积极预防 及时发现
快速响应 力保恢复
Squid是一个运行于Linux/Unix系统下的Web服务代理程序,它提供了对超文本缓冲协议的支持...
发布时间:2002-03-11 信息来源:管理员

CNCVE编号:CNCVE-20020035 CVE编号:CAN-2002-0067 安全级别:高 漏洞中文描述: Squid是一个运行于Linux/Unix系统下的Web服务代理程序,它提供了对超文本缓冲协议的支持(Hyper Text Caching Protocol),HTCP在RFC2757中有定义,用于提供对缓存的管理。在大多数默认安装情况下,这个支持选项是关闭的,但在编译时指定‘--enable-htcp’选项则可以打开此缓冲功能的支持。Squid实现上存在一个问题,使Squid的使用者无法在程序运行时配置HTCP支持选项的打开和关闭。虽然在Squid的文档中说明了对HTCP的是否支持可以在Squid的配置文件中指定,然而实际情况是HTCP支持选项一旦被编译进Squid,对HTCP的支持就一直处于打开状态。这导致在Squid运行期间管理员无法控制此支持选项的打开或关闭状态,即使在squid.conf中设置了"htcp_port 0"。这可能导致攻击者绕过预期的访问限制。 漏洞英文描述: Squid is one of web server proxy programs in Linux/Unix system,which supports Hyper TextCaching Protocol,provide management for caching,that is defined in RFC2757.As most default installation,this support fuction is disabled,but user can enable this fuction by specified ‘--enable-htcp’ in configuration.The optional HTCP interface cannot be properly disabled from squid.conf even if the documentation claims it can. The HTCP interface to Squid is not enabled by default, but can be enabled at compile time using the --enable-htcp configure option and some vendors distribute Squid binaries with HTCP enabled. 漏洞参考: http://archives.neohapsis.com/archives/bugtraq/2002-02/0230.html http://www.squid-cache.org/Advisories/SQUID-2002_1.txt ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:12.squid.asc https://www.redhat.com/support/errata/RHSA-2002-029.htm 系统类型:其他 漏洞类型:设计错误