4

CVE-2010-0308

lib/rfc1035.c in Squid 2.x, 3.0 through 3.0.STABLE22, and 3.1 through 3.1.0.15 allows remote attackers to cause a denial of service (assertion failure) via a crafted DNS packet that only contains a header.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Squid-cacheSquid Version2.0
Squid-cacheSquid Version2.1
Squid-cacheSquid Version2.2
Squid-cacheSquid Version2.3
Squid-cacheSquid Version2.4
Squid-cacheSquid Version2.5
Squid-cacheSquid Version2.6
Squid-cacheSquid Version2.7
Squid-cacheSquid Version3.0
Squid-cacheSquid Version3.0.stable1
Squid-cacheSquid Version3.0.stable2
Squid-cacheSquid Version3.0.stable3
Squid-cacheSquid Version3.0.stable4
Squid-cacheSquid Version3.0.stable5
Squid-cacheSquid Version3.0.stable6
Squid-cacheSquid Version3.0.stable7
Squid-cacheSquid Version3.0.stable8
Squid-cacheSquid Version3.0.stable9
Squid-cacheSquid Version3.0.stable11
Squid-cacheSquid Version3.0.stable12
Squid-cacheSquid Version3.0.stable13
Squid-cacheSquid Version3.0.stable14
Squid-cacheSquid Version3.0.stable15
Squid-cacheSquid Version3.0.stable16
Squid-cacheSquid Version3.0.stable17
Squid-cacheSquid Version3.0.stable18
Squid-cacheSquid Version3.0.stable19
Squid-cacheSquid Version3.0.stable20
Squid-cacheSquid Version3.0.stable21
Squid-cacheSquid Version3.0.stable22
Squid-cacheSquid Version3.1
Squid-cacheSquid Version3.1.0.1
Squid-cacheSquid Version3.1.0.2
Squid-cacheSquid Version3.1.0.3
Squid-cacheSquid Version3.1.0.4
Squid-cacheSquid Version3.1.0.5
Squid-cacheSquid Version3.1.0.6
Squid-cacheSquid Version3.1.0.7
Squid-cacheSquid Version3.1.0.8
Squid-cacheSquid Version3.1.0.9
Squid-cacheSquid Version3.1.0.10
Squid-cacheSquid Version3.1.0.11
Squid-cacheSquid Version3.1.0.12
Squid-cacheSquid Version3.1.0.13
Squid-cacheSquid Version3.1.0.14
Squid-cacheSquid Version3.1.0.15
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 16.82% 0.947
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.