G05-32p01
CVSS:
5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P)
False Positive:
t
Variants:
1
Year:
2005
Description
This strike exploits a vulnerability within the NTLM authentication mechanism implemented in the Squid web proxy/cache. During the NTLM authentication process, a malformed type-3 authentication message can cause the NTLM module of a vulnerable Squid server to dereference a null pointer. An attacker can exploit this vulnerability to create a denial of service condition. The DoS condition will directly affect the authentication session of the user that caused it, and may affect sessions performing authentication at the time of exploitation. This vulnerability does not pose any significant risk, as ongoing, established sessions and future sessions will not be affected by a successful exploitation. In a successful attack case, the child helper process spawned by the vulnerable Squid proxy server to handle the NTLM authentication handshake will terminate generating an error in the system logs. Due to the fact that the NTLM module is automatically restarted to process further authentication requests, subsequent connections are not affected by the attack. Current active connections are not affected by a successful attack.
CVE
References
http://secunia.com/advisories/13789