7.5
CVSSv2

CVE-2013-4115

Published: 09/08/2013 Updated: 30/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in the idnsALookup function in dns_internal.cc in Squid 3.2 up to and including 3.2.11 and 3.3 up to and including 3.3.6 allows remote malicious users to cause a denial of service (memory corruption and server termination) via a long name in a DNS lookup request.

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse opensuse 12.3

opensuse opensuse 11.4

opensuse opensuse 12.2

squid-cache squid 3.2.0.2

squid-cache squid 3.2.0.3

squid-cache squid 3.3.4

squid-cache squid 3.3.5

squid-cache squid 3.2.0.8

squid-cache squid 3.2.0.9

squid-cache squid 3.3.2

squid-cache squid 3.3.3

squid-cache squid 3.2.0.4

squid-cache squid 3.2.0.5

squid-cache squid 3.3.0

squid-cache squid 3.3.0.2

squid-cache squid 3.3.6

squid-cache squid 3.2.0.6

squid-cache squid 3.2.0.7

squid-cache squid 3.3.0.3

squid-cache squid 3.3.1

Vendor Advisories

Debian Bug report logs - #716743 squid3: CVE-2013-4115 CVE-2013-4123 Package: squid3; Maintainer for squid3 is Luigi Gangitano <luigi@debianorg>; Source for squid3 is src:squid (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Fri, 12 Jul 2013 06:36:02 UTC Severity: grave Tags: jessie, pa ...
A flaw was found in the way Squid handled malformed HTTP Range headers A remote attacker able to send HTTP requests to the Squid proxy could use this flaw to crash Squid (CVE-2014-3609) A buffer overflow flaw was found in Squid's DNS lookup module A remote attacker able to send HTTP requests to the Squid proxy could use this flaw to crash Squid ...
A flaw was found in the way Squid handled malformed HTTP Range headers A remote attacker able to send HTTP requests to the Squid proxy could use this flaw to crash Squid (CVE-2014-3609) A buffer overflow flaw was found in Squid's DNS lookup module A remote attacker able to send HTTP requests to the Squid proxy could use this flaw to crash Squid ...
A buffer overflow flaw was found in Squid's DNS lookup module A remote attacker able to send HTTP requests to the Squid proxy could use this flaw to crash Squid ...