CVE Vulnerabilities

CVE-2010-2951

Published: Oct 12, 2010 | Modified: Oct 13, 2010
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
5 LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM

dns_internal.cc in Squid 3.1.6, when IPv6 DNS resolution is not enabled, accesses an invalid socket during an IPv4 TCP DNS query, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via vectors that trigger an IPv4 DNS response with the TC bit set.

Affected Software

Name Vendor Start Version End Version
Squid Squid-cache 3.1.6 (including) 3.1.6 (including)
Squid3 Ubuntu jaunty *
Squid3 Ubuntu maverick *

References