5

CVE-2011-4096

The idnsGrokReply function in Squid before 3.1.16 does not properly free memory, which allows remote attackers to cause a denial of service (daemon abort) via a DNS reply containing a CNAME record that references another CNAME record that contains an empty A record.

Data is provided by the National Vulnerability Database (NVD)
Squid-cacheSquid Version <= 3.1.15
Squid-cacheSquid Version3.0
Squid-cacheSquid Version3.0 Editionpre1
Squid-cacheSquid Version3.0 Editionpre2
Squid-cacheSquid Version3.0 Editionpre3
Squid-cacheSquid Version3.0 Editionpre4
Squid-cacheSquid Version3.0 Editionpre5
Squid-cacheSquid Version3.0 Editionpre6
Squid-cacheSquid Version3.0 Editionpre7
Squid-cacheSquid Version3.0 Editionstable1
Squid-cacheSquid Version3.0 Editionstable10
Squid-cacheSquid Version3.0 Editionstable11
Squid-cacheSquid Version3.0 Editionstable12
Squid-cacheSquid Version3.0 Editionstable13
Squid-cacheSquid Version3.0 Editionstable14
Squid-cacheSquid Version3.0 Editionstable15
Squid-cacheSquid Version3.0 Editionstable2
Squid-cacheSquid Version3.0 Editionstable3
Squid-cacheSquid Version3.0 Editionstable4
Squid-cacheSquid Version3.0 Editionstable5
Squid-cacheSquid Version3.0 Editionstable6
Squid-cacheSquid Version3.0 Editionstable7
Squid-cacheSquid Version3.0 Editionstable8
Squid-cacheSquid Version3.0 Editionstable9
Squid-cacheSquid Version3.0 Updaterc1 Editionstable11
Squid-cacheSquid Version3.0 Updaterc4
Squid-cacheSquid Version3.0.stable1
Squid-cacheSquid Version3.0.stable2
Squid-cacheSquid Version3.0.stable3
Squid-cacheSquid Version3.0.stable4
Squid-cacheSquid Version3.0.stable5
Squid-cacheSquid Version3.0.stable6
Squid-cacheSquid Version3.0.stable7
Squid-cacheSquid Version3.0.stable8
Squid-cacheSquid Version3.0.stable9
Squid-cacheSquid Version3.0.stable10
Squid-cacheSquid Version3.0.stable11
Squid-cacheSquid Version3.0.stable11 Updaterc1
Squid-cacheSquid Version3.0.stable12
Squid-cacheSquid Version3.0.stable13
Squid-cacheSquid Version3.0.stable14
Squid-cacheSquid Version3.0.stable15
Squid-cacheSquid Version3.0.stable16
Squid-cacheSquid Version3.0.stable16 Updaterc1
Squid-cacheSquid Version3.0.stable17
Squid-cacheSquid Version3.0.stable18
Squid-cacheSquid Version3.0.stable19
Squid-cacheSquid Version3.0.stable20
Squid-cacheSquid Version3.0.stable21
Squid-cacheSquid Version3.0.stable22
Squid-cacheSquid Version3.0.stable23
Squid-cacheSquid Version3.0.stable24
Squid-cacheSquid Version3.0.stable25
Squid-cacheSquid Version3.1
Squid-cacheSquid Version3.1.0.1
Squid-cacheSquid Version3.1.0.2
Squid-cacheSquid Version3.1.0.3
Squid-cacheSquid Version3.1.0.4
Squid-cacheSquid Version3.1.0.5
Squid-cacheSquid Version3.1.0.6
Squid-cacheSquid Version3.1.0.7
Squid-cacheSquid Version3.1.0.8
Squid-cacheSquid Version3.1.0.9
Squid-cacheSquid Version3.1.0.10
Squid-cacheSquid Version3.1.0.11
Squid-cacheSquid Version3.1.0.12
Squid-cacheSquid Version3.1.0.13
Squid-cacheSquid Version3.1.0.14
Squid-cacheSquid Version3.1.0.15
Squid-cacheSquid Version3.1.0.16
Squid-cacheSquid Version3.1.0.17
Squid-cacheSquid Version3.1.0.18
Squid-cacheSquid Version3.1.1
Squid-cacheSquid Version3.1.2
Squid-cacheSquid Version3.1.3
Squid-cacheSquid Version3.1.4
Squid-cacheSquid Version3.1.5
Squid-cacheSquid Version3.1.5.1
Squid-cacheSquid Version3.1.6
Squid-cacheSquid Version3.1.7
Squid-cacheSquid Version3.1.8
Squid-cacheSquid Version3.1.9
Squid-cacheSquid Version3.1.10
Squid-cacheSquid Version3.1.11
Squid-cacheSquid Version3.1.12
Squid-cacheSquid Version3.1.13
Squid-cacheSquid Version3.1.14
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 62.49% 0.983
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P