PT-2013-4856 · Squid+3 · Squid+4
Nathan Hoad
·
Publicado
2013-07-21
·
Atualizado
2018-10-30
·
CVE-2013-4115
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Squid versions 3.2 through 3.2.11
Squid versions 3.3 through 3.3.6
Description
The issue allows remote attackers to cause a denial of service, resulting in memory corruption and server termination, via a long name in a DNS lookup request. This is due to a buffer overflow in the
idnsALookup function.Recommendations
For Squid versions 3.2 through 3.2.11, update to a version outside of this range to resolve the issue.
For Squid versions 3.3 through 3.3.6, update to a version outside of this range to resolve the issue.
As a temporary workaround, consider restricting the length of names in DNS lookup requests to prevent exploitation.
Correção
DoS
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Centos
Red Hat
Squid
Squid Cache
Suse