CVE-2005-2917
published 2005-09-30CVE-2005-2917: Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, does not properly handle certain request sequences, which allows attackers to cause a…
PriorityP421medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.40%
87.6th percentile
Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, does not properly handle certain request sequences, which allows attackers to cause a denial of service (daemon restart).
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | squid | < squid 2.5.10-7 (bookworm) | squid 2.5.10-7 (bookworm) |
| squid | squid | <= 2.5.stable10 | — |
| squid | squid | — | — |
| squid | squid | >= 0 < 2.5.10-7 | 2.5.10-7 |
| squid | squid | >= 0 < 2.5.10-7 | 2.5.10-7 |
| squid | squid | >= 0 < 2.5.10-7 | 2.5.10-7 |
| squid | squid | >= 0 < 2.5.10-7 | 2.5.10-7 |
Detection & IOCsextracted from sources · hover to see the quote
- →Target Squid proxy servers running version 2.5.STABLE10 or earlier with NTLM authentication enabled; sending specially crafted NTLM authentication request sequences triggers an assert/crash (daemon restart) ↗
- →The vulnerability is specifically tied to the NTLM authentication scheme assert path in Squid; monitor for unexpected Squid daemon restarts when NTLM authentication is in use ↗
- →Sending specially crafted NTLM authentication requests to Squid caused the server to crash; detect anomalous or malformed NTLM negotiation sequences directed at Squid listeners ↗
- ·RHEL 2.1 is not affected because it does not ship the NTLM helper; the vulnerability only applies where the NTLM authentication helper is present and enabled ↗
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Squid vulnerability
vendor_ubuntu·2005-10-01
CVE-2005-2917 Squid vulnerability
Title: Squid vulnerability
Summary: Squid vulnerability
Mike Diggins discovered a remote Denial of Service vulnerability in
Squid. Sending specially crafted NTML authentication requests to Squid
caused the server to crash.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
security flaw
vendor_redhat·2005-09-15·CVSS 5.0
CVE-2005-2917 [MEDIUM] security flaw
security flaw
Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, does not properly handle certain request sequences, which allows attackers to cause a denial of service (daemon restart).
Debian
CVE-2005-2917: squid - Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, does not p...
vendor_debian·2005·CVSS 5.0
CVE-2005-2917 [MEDIUM] CVE-2005-2917: squid - Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, does not p...
Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, does not properly handle certain request sequences, which allows attackers to cause a denial of service (daemon restart).
Scope: local
bookworm: resolved (fixed in 2.5.10-7)
bullseye: resolved (fixed in 2.5.10-7)
forky: resolved (fixed in 2.5.10-7)
sid: resolved (fixed in 2.5.10-7)
trixie: resolved (fixed in 2.5.10-7)
GHSA
GHSA-5hg5-x4p6-wgf5: Squid 2
ghsa_unreviewed·2022-05-03
CVE-2005-2917 [MEDIUM] GHSA-5hg5-x4p6-wgf5: Squid 2
Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, does not properly handle certain request sequences, which allows attackers to cause a denial of service (daemon restart).
OSV
CVE-2005-2917: Squid 2
osv·2005-09-30·CVSS 5.0
CVE-2005-2917 [MEDIUM] CVE-2005-2917: Squid 2
Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, does not properly handle certain request sequences, which allows attackers to cause a denial of service (daemon restart).
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2005-2917 security flaw
bugzilla·2018-08-16·CVSS 5.0
CVE-2005-2917 [MEDIUM] CVE-2005-2917 security flaw
CVE-2005-2917 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, does not properly handle certain request sequences, which allows attackers to cause a denial of service (daemon restart).
Bugzilla
CVE-2005-2917 Squid malformed NTLM authentication DoS
bugzilla·2005-11-23·CVSS 5.0
CVE-2005-2917 [MEDIUM] CVE-2005-2917 Squid malformed NTLM authentication DoS
CVE-2005-2917 Squid malformed NTLM authentication DoS
+++ This bug was initially created as a clone of Bug #168378 +++
This issue comes from upstream:
http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE10-NTLM-scheme_assert
It seems that the squid server supports NTLM authentication, it is possible to
crash the squid server.
Discussion:
I split this bug from bug 168378 and am adding this to the RHEL3U7CanFix list.
Bug 168378 was on the RHEL3U7CanFix list, but that bug was for RHEL4.
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug r
Bugzilla
CVE-2005-2917 Squid malformed NTLM authentication DoS
bugzilla·2005-09-15·CVSS 5.0
CVE-2005-2917 [MEDIUM] CVE-2005-2917 Squid malformed NTLM authentication DoS
CVE-2005-2917 Squid malformed NTLM authentication DoS
This issue comes from upstream:
http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE10-NTLM-scheme_assert
It seems that the squid server supports NTLM authentication, it is possible to
crash the squid server.
Discussion:
This issue may also affect RHEL2.1 and RHEL3
---
RHEL2.1 isn't affected by this issue because it doesn't have NTLM helper...
---
I have removed this bug from the RHEL3U7CanFix list (bug 168424). This bug is
for RHEL4. I have filed bug 174029 to cover RHEL3U7.
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please
Bugzilla
Squid Multiple Vulnerabilities (CVE-2004-0541 CVE-2004-0832 CVE-2004-0918 CVE-2005-0094 CVE-2005-0095 CVE-2005-0096 CVE-2005-0097 CVE-2005-0446 CVE-2005-0626 CVE-2005-0718 CVE-1999-0710 CVE-2005-1345
bugzilla·2004-10-11·CVSS 7.5
CVE-2004-0541 [HIGH] Squid Multiple Vulnerabilities (CVE-2004-0541 CVE-2004-0832 CVE-2004-0918 CVE-2005-0094 CVE-2005-0095 CVE-2005-0096 CVE-2005-0097 CVE-2005-0446 CVE-2005-0626 CVE-2005-0718 CVE-1999-0710 CVE-2005-1345
Squid Multiple Vulnerabilities (CVE-2004-0541 CVE-2004-0832 CVE-2004-0918 CVE-2005-0094 CVE-2005-0095 CVE-2005-0096 CVE-2005-0097 CVE-2005-0446 CVE-2005-0626 CVE-2005-0718 CVE-1999-0710 CVE-2005-1345 CVE-2005-1519 CVE-2004-2479 CVE-2005-2794 CVE-2005-...
iDEFENSE reported on 2004-10-11 a vulnerability in the squid SNMP
module. This issue could lead to a potential DOS (it will restart
the server, dropping all open connections).
http://www.idefense.com/application/poi/display?id=152&type=vulnerabilities
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=135320
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=135319
------- Additional Comments From [email protected] 2004-10-11 19:30:05 ----
Patch available here:
http://www1.uk.squid-cache.org/squid/Versions/v2/2
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txtftp://patches.sgi.com/support/free/security/advisories/20060401-01-Uhttp://fedoranews.org/updates/FEDORA--.shtmlhttp://secunia.com/advisories/16992http://secunia.com/advisories/17015http://secunia.com/advisories/17050http://secunia.com/advisories/17177http://secunia.com/advisories/19161http://secunia.com/advisories/19532http://securitytracker.com/id?1014920http://www.debian.org/security/2005/dsa-828http://www.mandriva.com/security/advisories?name=MDKSA-2005:181http://www.novell.com/linux/security/advisories/2005_27_sr.htmlhttp://www.osvdb.org/19607http://www.redhat.com/support/errata/RHSA-2006-0045.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0052.htmlhttp://www.securityfocus.com/bid/14977http://www.ubuntu.com/usn/usn-192-1/https://exchange.xforce.ibmcloud.com/vulnerabilities/24282https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11580ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txtftp://patches.sgi.com/support/free/security/advisories/20060401-01-Uhttp://fedoranews.org/updates/FEDORA--.shtmlhttp://secunia.com/advisories/16992http://secunia.com/advisories/17015http://secunia.com/advisories/17050http://secunia.com/advisories/17177http://secunia.com/advisories/19161http://secunia.com/advisories/19532http://securitytracker.com/id?1014920http://www.debian.org/security/2005/dsa-828http://www.mandriva.com/security/advisories?name=MDKSA-2005:181http://www.novell.com/linux/security/advisories/2005_27_sr.htmlhttp://www.osvdb.org/19607http://www.redhat.com/support/errata/RHSA-2006-0045.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0052.htmlhttp://www.securityfocus.com/bid/14977http://www.ubuntu.com/usn/usn-192-1/https://exchange.xforce.ibmcloud.com/vulnerabilities/24282https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11580
2005-09-30
Published