Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.100774
Categoría:Buffer overflow
Título:Squid 3.1.6 'DNS' Reply Remote Buffer Overflow Vulnerability
Resumen:Squid is prone to a remote buffer-overflow vulnerability; because it fails to perform adequate boundary checks on user-supplied data.
Descripción:Summary:
Squid is prone to a remote buffer-overflow vulnerability
because it fails to perform adequate boundary checks on user-supplied data.

Vulnerability Impact:
An attacker can exploit this issue to execute arbitrary code
within the context of the affected application. Failed exploit attempts will result in a
denial-of-service condition.

Affected Software/OS:
Squid version 3.1.6 is vulnerable. Other versions may
also be affected.

Solution:
Updates are available. Please see the references for details.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2010-2951
[oss-security] 20100824 CVE Request -- Squid v3.1.6 -- DoS (crash) while processing large DNS replies with no IPv6 resolver present
http://www.openwall.com/lists/oss-security/2010/08/24/6
[oss-security] 20100825 Re: CVE Request -- Squid v3.1.6 -- DoS (crash) while processing large DNS replies with no IPv6 resolver present
http://www.openwall.com/lists/oss-security/2010/08/24/7
http://www.openwall.com/lists/oss-security/2010/08/25/2
http://www.openwall.com/lists/oss-security/2010/08/25/6
[squid-users] 20100824 Squid 3.1.7 is available
http://marc.info/?l=squid-users&m=128263555724981&w=2
http://bazaar.launchpad.net/~squid/squid/3.1/revision/10072
http://bugs.gentoo.org/show_bug.cgi?id=334263
http://bugs.squid-cache.org/show_bug.cgi?id=3009
http://bugs.squid-cache.org/show_bug.cgi?id=3021
http://www.squid-cache.org/Versions/v3/3.1/changesets/squid-3.1-10072.patch
https://bugzilla.redhat.com/show_bug.cgi?id=626927
CopyrightCopyright (C) 2010 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.