Lucene search

K
freebsdFreeBSD296ECB59-0F6B-11DF-8BAB-0019996BC1F7
HistoryJan 14, 2010 - 12:00 a.m.

squid -- Denial of Service vulnerability in DNS handling

2010-01-1400:00:00
vuxml.freebsd.org
12

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:N/A:P

0.136 Low

EPSS

Percentile

95.7%

Squid security advisory 2010:1 reports:

Due to incorrect data validation Squid is vulnerable to a denial
of service attack when processing specially crafted DNS packets.
This problem allows any trusted client or external server who can
determine the squid receiving port to perform a short-term denial
of service attack on the Squid service.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchsquid= 2.7.1UNKNOWN
FreeBSDanynoarchsquid< 2.7.7_3UNKNOWN

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:N/A:P

0.136 Low

EPSS

Percentile

95.7%