Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.100774
Kategorie:Buffer overflow
Titel:Squid 3.1.6 'DNS' Reply Remote Buffer Overflow Vulnerability
Zusammenfassung:Squid is prone to a remote buffer-overflow vulnerability; because it fails to perform adequate boundary checks on user-supplied data.
Beschreibung:Summary:
Squid is prone to a remote buffer-overflow vulnerability
because it fails to perform adequate boundary checks on user-supplied data.

Vulnerability Impact:
An attacker can exploit this issue to execute arbitrary code
within the context of the affected application. Failed exploit attempts will result in a
denial-of-service condition.

Affected Software/OS:
Squid version 3.1.6 is vulnerable. Other versions may
also be affected.

Solution:
Updates are available. Please see the references for details.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2010-2951
[oss-security] 20100824 CVE Request -- Squid v3.1.6 -- DoS (crash) while processing large DNS replies with no IPv6 resolver present
http://www.openwall.com/lists/oss-security/2010/08/24/6
[oss-security] 20100825 Re: CVE Request -- Squid v3.1.6 -- DoS (crash) while processing large DNS replies with no IPv6 resolver present
http://www.openwall.com/lists/oss-security/2010/08/24/7
http://www.openwall.com/lists/oss-security/2010/08/25/2
http://www.openwall.com/lists/oss-security/2010/08/25/6
[squid-users] 20100824 Squid 3.1.7 is available
http://marc.info/?l=squid-users&m=128263555724981&w=2
http://bazaar.launchpad.net/~squid/squid/3.1/revision/10072
http://bugs.gentoo.org/show_bug.cgi?id=334263
http://bugs.squid-cache.org/show_bug.cgi?id=3009
http://bugs.squid-cache.org/show_bug.cgi?id=3021
http://www.squid-cache.org/Versions/v3/3.1/changesets/squid-3.1-10072.patch
https://bugzilla.redhat.com/show_bug.cgi?id=626927
CopyrightCopyright (C) 2010 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.