[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2304-1 squid3 -- buffer overflow

ID: oval:org.secpod.oval:def:600619Date: (C)2011-10-13   (M)2023-11-09
Class: PATCHFamily: unix




Ben Hawkes discovered that squid3, a full featured Web Proxy cache , is vulnerable to a buffer overflow when processing gopher server replies. An attacker can exploit this flaw by connecting to a gopher server that returns lines longer than 4096 bytes. This may result in denial of service conditions or the possibly the execution of arbitrary code with rights of the squid daemon.

Platform:
Debian 5.0
Debian 6.0
Product:
squid3
Reference:
DSA-2304-1
CVE-2011-3205
CVE    1
CVE-2011-3205
CPE    3
cpe:/a:squid-cache:squid3
cpe:/o:debian:debian_linux:5.0
cpe:/o:debian:debian_linux:6.0

© SecPod Technologies