PT-2013-4856 · Squid+3 · Squid+4

Nathan Hoad

·

Publicado

2013-07-21

·

Atualizado

2018-10-30

·

CVE-2013-4115

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Squid versions 3.2 through 3.2.11 Squid versions 3.3 through 3.3.6
Description The issue allows remote attackers to cause a denial of service, resulting in memory corruption and server termination, via a long name in a DNS lookup request. This is due to a buffer overflow in the idnsALookup function.
Recommendations For Squid versions 3.2 through 3.2.11, update to a version outside of this range to resolve the issue. For Squid versions 3.3 through 3.3.6, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting the length of names in DNS lookup requests to prevent exploitation.

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CESA-2014_1148
CVE-2013-4115
MGASA-2013-0227
MGASA-2013-0228
RHSA-2014:1148
RHSA-2014_1148
SUSE-SU-2013_1467-1
SUSE-SU-2016:2089-1

Produtos afetados

Centos
Red Hat
Squid
Squid Cache
Suse