Description
The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a denial of service (server restart) via certain SNMP packets with negative length fields that trigger a memory allocation error.
Affected products
- gentoo / linux
- openpkg / openpkg2.1 – 2.1
- openpkg / openpkg2.2 – 2.2
- openpkg / openpkgcurrent – current
- RedHat / fedora_corecore_2.0 – core_2.0
- squid / squid2.4 – 2.4
- squid / squid2.4_.stable2 – 2.4_.stable2
- squid / squid2.4_.stable6 – 2.4_.stable6
- squid / squid2.4_.stable7 – 2.4_.stable7
- squid / squid2.5_.stable1 – 2.5_.stable1
- squid / squid2.5_.stable3 – 2.5_.stable3
- squid / squid2.5_.stable5 – 2.5_.stable5
- squid / squid2.5_.stable6 – 2.5_.stable6
- squid / squid3.0_pre1 – 3.0_pre1
- squid / squid3.0_pre2 – 3.0_pre2
- squid / squid3.0_pre3 – 3.0_pre3
- squid / squid2.5_.stable4 – 2.5_.stable4
- squid / squid2.0_patch2 – 2.0_patch2
- squid / squid2.1_patch2 – 2.1_patch2
- squid / squid2.3_.stable4 – 2.3_.stable4
- squid / squid2.3_.stable5 – 2.3_.stable5
- trustix / secure_linux1.5 – 1.5
- trustix / secure_linux2.0 – 2.0
- trustix / secure_linux2.1 – 2.1
- Ubuntu / ubuntu_linux4.1 – 4.1
- Ubuntu / ubuntu_linux4.1 – 4.1
References
- MISChttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000923
- MISChttp://www.securityfocus.com/bid/11385
- MISCftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.16/SCOSA-2005.16.txt
- MISChttp://www.redhat.com/support/errata/RHSA-2004-591.html
- MISChttp://www.idefense.com/application/poi/display?id=152&type=vulnerabilities&flashstatus=false
- VENDOR_ADVISORYhttp://www.squid-cache.org/Advisories/SQUID-2004_3.txt
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10931
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2008/1969/references
- VENDOR_ADVISORYhttp://secunia.com/advisories/30967
- MISChttp://fedoranews.org/updates/FEDORA--.shtml
- MAILING_LISThttp://lists.opensuse.org/opensuse-security-announce/2008-07/msg00001.html
- MISChttps://www.redhat.com/archives/fedora-package-announce/2008-July/msg00122.html
- MAILING_LISThttp://marc.info/?l=bugtraq&m=109913064629327&w=2
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/17688
- VENDOR_ADVISORYhttp://secunia.com/advisories/30914
- VENDOR_ADVISORYhttp://www.squid-cache.org/Advisories/SQUID-2008_1.txt
- MISChttp://www.gentoo.org/security/en/glsa/glsa-200410-15.xml