4
CVSSv2

CVE-2010-0308

Published: 03/02/2010 Updated: 19/09/2017
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

lib/rfc1035.c in Squid 2.x, 3.0 up to and including 3.0.STABLE22, and 3.1 up to and including 3.1.0.15 allows remote malicious users to cause a denial of service (assertion failure) via a crafted DNS packet that only contains a header.

Vulnerable Product Search on Vulmon Subscribe to Product

squid-cache squid 3.0

squid-cache squid 2.6

squid-cache squid 2.7

squid-cache squid 3.1.0.6

squid-cache squid 3.1.0.7

squid-cache squid 3.1.0.11

squid-cache squid 3.0.stable22

squid-cache squid 3.0.stable15

squid-cache squid 3.0.stable14

squid-cache squid 3.0.stable6

squid-cache squid 3.0.stable5

squid-cache squid 2.1

squid-cache squid 2.0

squid-cache squid 3.1

squid-cache squid 3.1.0.1

squid-cache squid 3.1.0.8

squid-cache squid 3.1.0.9

squid-cache squid 3.1.0.10

squid-cache squid 3.0.stable21

squid-cache squid 3.0.stable20

squid-cache squid 3.0.stable13

squid-cache squid 3.0.stable12

squid-cache squid 3.0.stable4

squid-cache squid 3.0.stable3

squid-cache squid 3.0.stable2

squid-cache squid 2.2

squid-cache squid 2.3

squid-cache squid 3.1.0.2

squid-cache squid 3.1.0.3

squid-cache squid 3.1.0.15

squid-cache squid 3.1.0.14

squid-cache squid 3.0.stable19

squid-cache squid 3.0.stable18

squid-cache squid 3.0.stable11

squid-cache squid 3.0.stable9

squid-cache squid 3.0.stable1

squid-cache squid 2.4

squid-cache squid 2.5

squid-cache squid 3.1.0.4

squid-cache squid 3.1.0.5

squid-cache squid 3.1.0.13

squid-cache squid 3.1.0.12

squid-cache squid 3.0.stable17

squid-cache squid 3.0.stable16

squid-cache squid 3.0.stable8

squid-cache squid 3.0.stable7

Vendor Advisories

Synopsis Low: squid security and bug fix update Type/Severity Security Advisory: Low Topic An updated squid package that fixes two security issues and several bugs isnow available for Red Hat Enterprise Linux 5The Red Hat Security Response Team has rated this update as having lowsecurity impact Common Vul ...
It was discovered that Squid incorrectly handled certain auth headers A remote attacker could exploit this with a specially-crafted auth header and cause Squid to go into an infinite loop, resulting in a denial of service This issue only affected Ubuntu 810, 904 and 910 (CVE-2009-2855) ...
Two denial of service vulnerabilities have been discovered in squid and squid3, a web proxy The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-2855 Bastian Blank discovered that it is possible to cause a denial of service via a crafted auth header with certain comma delimiters CVE-2010-0308 Tomas Hoger d ...
Debian Bug report logs - #572553 CVE-2010-0639: HTCP DoS Package: squid; Maintainer for squid is Luigi Gangitano <luigi@debianorg>; Source for squid is src:squid (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Thu, 4 Mar 2010 20:51:09 UTC Severity: important Tags: security Found in ve ...
Debian Bug report logs - #575747 CVE-2010-0308: denial of service via a crafted DNS packet Package: squid3; Maintainer for squid3 is Luigi Gangitano <luigi@debianorg>; Source for squid3 is src:squid (PTS, buildd, popcon) Reported by: Giuseppe Iuculano <iuculano@debianorg> Date: Sun, 28 Mar 2010 21:27:02 UTC Severi ...
Debian Bug report logs - #534982 squid - DoS in external auth header parser Package: squid; Maintainer for squid is Luigi Gangitano <luigi@debianorg>; Source for squid is src:squid (PTS, buildd, popcon) Reported by: Bastian Blank <waldi@debianorg> Date: Sun, 28 Jun 2009 18:21:02 UTC Severity: critical Tags: fixed- ...