Update Protection against Squid Proxy TRACE Request Denial of Service Vulnerability
| Check Point Reference: | CPAI-2007-084 | |
| Date Published: | ||
| Severity: | ||
| Last Updated: | ||
| Source: | Secunia Advisory: SA24611 | |
| Industry Reference(s): | CVE-2007-1560 | |
| Protection Provided by: |
VPN-1
|
|
| Who is Vulnerable? Squid Web Proxy Cache prior to 2.6.STABLE12 | ||
| Vulnerability Description A denial of service vulnerability has been reported in Squid proxy. The Squid proxy server is a popular open source, Internet proxy and web caching application. A remote attacker may exploit this issue to create a denial of service condition and crash the vulnerable application. |
||
|
Update/Patch Available Upgrade to Squid version 2.6.STABLE12: Squid-Cache |
|
|
Vulnerability Details The vulnerability is due to an error within the squid proxy when processing malformed HTTP TRACE requests. A remote attacker can exploit this flaw by specially crafting a TRACE request and sending it to a vulnerable system. Successful exploitation may allow an attacker to create a denial of service condition on an affected server. |
Protection Overview
By enabling this protection, SmartDefense will detect and block specially crafted TRACE requests sent to the Squid proxy server.
In order for the protection to be activated, update your VPN-1/InterSpect/Connectra product to the latest SmartDefense update. For information on how to update SmartDefense, go to SBP-2006-05, Protection tab and select the version of your choice.
To configure the defense, select your product from the list below and follow the related protection steps.
Additional Information
The update released on September 18, 2007 includes the following protections:
Squid Proxy TRACE Request Denial of Service Vulnerability (CPAI-2007-084)
Microsoft Exchange Server iCal Denial of Service Vulnerability (MS07-026) CPAI-2007-081
Microsoft Exchange SMTP MIME Vulnerability (MS07-026) CPAI-2007-094
Yahoo! Widgets YDP ActiveX Control Buffer Overflow Vulnerability (CPAI-2007-105)
Multiple Trend Micro ServerProtect Buffer Overflow Vulnerabilities (CPAI-2007-106)