Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 69712 - www-proxy/squid cachemgr.cgi Unauthorized Connection Vulnerability
Summary: www-proxy/squid cachemgr.cgi Unauthorized Connection Vulnerability
Status: RESOLVED WORKSFORME
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://www.securityfocus.com/bid/2059/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2004-11-01 06:09 UTC by Robert Muchacki (RETIRED)
Modified: 2004-11-05 05:44 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Muchacki (RETIRED) gentoo-dev 2004-11-01 06:09:22 UTC
Squid cachemgr.cgi Unauthorized Connection Vulnerability

More info: http://www.securityfocus.com/bid/2059/discussion/

There is already an exploit for this one.

Reproducible: Always
Steps to Reproduce:
1.
2.
3.
Comment 1 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2004-11-01 06:21:25 UTC
Andrew please verify and patch if needed.
Comment 2 Thierry Carrez (RETIRED) gentoo-dev 2004-11-01 07:21:25 UTC
In fact there is no patch... The solution is not to enable cachemgr.cgi access to anyone. RedHat used to ship with cachemgr.cgi accessible in Apache cgi-bin.

I don't have squid installed, but I don't think we install cachemgr.cgi world-accessible by default... Andrew, please confirm/debunk.
Comment 3 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2004-11-02 13:45:05 UTC
cyfred was last on irc over two weeks ago and has no devaway.

I guess this snippet from default configuration file squid.conf is enough:

# Only allow cachemgr access from localhost
http_access allow manager localhost
http_access deny manager
Comment 4 Andrew Bevitt 2004-11-02 22:17:42 UTC
Im buried up to my armpits in assignments (checked mail today for first time in a week or so) until at least this monday, feel free to change this anyone that wants to.
Comment 5 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2004-11-04 11:34:16 UTC
I'm not sure wether the default configuration options from comment #3 is enough. Someone with Squid knowledge please verify.
Comment 6 Thierry Carrez (RETIRED) gentoo-dev 2004-11-05 05:44:54 UTC
Default configuration in Gentoo is to allow only cachemgr access from localhost. Furthermore most actions require a password... The old bug was about putting cachemgr.cgi directly in an accessible cgi-bin, and it's definitely not the case here.

Closing as WORKSFORME... Please prove me wrong by detailing how this applies to Gentoo default Squid.