5
CVSSv2

CVE-2010-3072

Published: 20/09/2010 Updated: 14/01/2011
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The string-comparison functions in String.cci in Squid 3.x prior to 3.1.8 and 3.2.x prior to 3.2.0.2 allow remote malicious users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request.

Vulnerable Product Search on Vulmon Subscribe to Product

squid-cache squid 3.0.stable3

squid-cache squid 3.0.stable4

squid-cache squid 3.0.stable11

squid-cache squid 3.0.stable18

squid-cache squid 3.0.stable19

squid-cache squid 3.0

squid-cache squid 3.1

squid-cache squid 3.1.0.7

squid-cache squid 3.1.0.8

squid-cache squid 3.1.0.16

squid-cache squid 3.1.0.17

squid-cache squid 3.1.5.1

squid-cache squid 3.1.6

squid-cache squid 3.0.stable7

squid-cache squid 3.0.stable8

squid-cache squid 3.0.stable14

squid-cache squid 3.0.stable15

squid-cache squid 3.0.stable22

squid-cache squid 3.0.stable23

squid-cache squid 3.1.0.3

squid-cache squid 3.1.0.4

squid-cache squid 3.1.0.11

squid-cache squid 3.1.0.12

squid-cache squid 3.1.0.13

squid-cache squid 3.1.2

squid-cache squid 3.1.3

squid-cache squid 3.0.stable1

squid-cache squid 3.0.stable2

squid-cache squid 3.0.stable9

squid-cache squid 3.0.stable10

squid-cache squid 3.0.stable16

squid-cache squid 3.0.stable17

squid-cache squid 3.0.stable24

squid-cache squid 3.0.stable25

squid-cache squid 3.1.0.5

squid-cache squid 3.1.0.6

squid-cache squid 3.1.0.14

squid-cache squid 3.1.0.15

squid-cache squid 3.1.4

squid-cache squid 3.1.5

squid-cache squid 3.0.stable5

squid-cache squid 3.0.stable6

squid-cache squid 3.0.stable12

squid-cache squid 3.0.stable13

squid-cache squid 3.0.stable20

squid-cache squid 3.0.stable21

squid-cache squid 3.1.0.1

squid-cache squid 3.1.0.2

squid-cache squid 3.1.0.9

squid-cache squid 3.1.0.10

squid-cache squid 3.1.0.18

squid-cache squid 3.1.1

squid-cache squid 3.1.7

Vendor Advisories

Debian Bug report logs - #596086 CVE-2010-3072: DoS triggered by internal error in string handling Package: squid3; Maintainer for squid3 is Luigi Gangitano <luigi@debianorg>; Source for squid3 is src:squid (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: Wed, 8 Sep 2010 15:18 ...
Phil Oester discovered that Squid-3, a fully featured Web Proxy cache, is prone to a denial of service attack via a specially crafted request that includes empty strings For the stable distribution (lenny), this problem has been fixed in version 30STABLE8-3+lenny4 For the testing distribution (squeeze), this problem will be fixed soon For the ...