SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

Squid Analysis Report Generator <= 2.2.3.1 buffer overflow


Arrow  SecurityAlert : 6898
Arrow  CVE : CVE-2008-7249
Arrow  CWE : CWE-119
Arrow  SecurityRisk : High  Security Risk High  (About)
Arrow  Remote Exploit : Yes
Arrow  Local Exploit : No
Arrow  Victim interaction required : Yes
Arrow  Exploit Available : Yes
Arrow  Credit : L4teral
Arrow  Published : 02.01.2010

Arrow  Affected Software : sarg:squid_analysis_report_generator:2.2.3.1 and previous versions
sarg:squid_analysis_report_generator:2.2.3
sarg:squid_analysis_report_generator:2.2.2
sarg:squid_analysis_report_generator:2.2.1
sarg:squid_analysis_report_generator:2.2
sarg:squid_analysis_report_generator:2.1



Arrow  Advisory Content :  

======================================================================
Squid Analysis Report Generator <= 2.2.3.1 buffer overflow
======================================================================

Author: L4teral <l4teral [4t] gmail com>
Impact: buffer overflow
Status: fixed version available

------------------------------
Affected software description:
------------------------------

Application: Squid Analysis Report Generator
Version: <= 2.2.3.1
Vendor: http://sarg.sourceforge.net

Description:
Squid Analysis Report Generator is a tool that allow you to view
"where" your users are going to on the Internet.

--------------
Vulnerability:
--------------

Execution of arbitrary code is possible by executing sarg with
specially crafted squid log files (access and useragent log).

The access.log has to be manually created to trigger the exploit,
as squid will not allow malformed HTTP methods.

The useragent log is more critical, as this vulnerability can be
exploited by just passing the useragent string within a request
to the squid proxy.

------------
PoC/Exploit:
------------

Edit a normal access log and set the request method to an overly long
string.

Edit a normal useragent log and set the useragent field to an overly
long string or send a request to the Squid proxy server passing an
overly long string as useragent in the HTTP header.

---------
Solution:
---------

Upgrade to version 2.2.4 or higher.

---------
Timeline:
---------

2008-01-28 - vendor informed
2008-01-28 - vendor responded
2008-03-02 - vendor released new version
2008-03-03 - public disclosure



Arrow  References :

http://www.vupen.com/english/advisories/2008/0749
http://www.securityfocus.com/archive/1/archive/1/489018/100/0/threaded
http://sourceforge.net/project/shownotes.php?release_id=581212




Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

libc/fnmatch(3) DoS

Security Risk Medium- 2011-05-13

Allow attacker to denial of service apache 2.2.17 server

Apache RSS Apache Alert

» Apache HTTP Server Denial
   of Service Vulnerability

» Multiple Vendors
   libc/fnmatch(3) DoS (incl
   apache poc)

» Apache Continuum
   cross-site scripting
   vulnerability

» Apache Tomcat DoS
   Vulnerability

PHP RSS PHP Alert

» PHP Hashtables Denial of
   Service

» PHP 5.3.6 multiple null
   pointer dereference

» PHP 5.3.6 ZipArchive
   invalid use glob(3)

» libzip 0.9.3
   _zip_name_locate NULL
   Pointer Dereference (incl
   PHP 5.3.5)

ADT

Protect your family and valuables with Home Security Systems

Copyright © SecurityReason.com. All Rights Reserved.