Back to search
CVE-2010-2951
Published: Oct 12, 2010
Modified: Aug 7, 2024
PUBLISHED
Description
dns_internal.cc in Squid 3.1.6, when IPv6 DNS resolution is not enabled, accesses an invalid socket during an IPv4 TCP DNS query, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via vectors that trigger an IPv4 DNS response with the TC bit set.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://bugs.squid-cache.org/show_bug.cgi?id=3009
x_refsource_CONFIRM
[squid-users] 20100824 Squid 3.1.7 is available
mailing-list
x_refsource_MLIST
https://bugzilla.redhat.com/show_bug.cgi?id=626927
x_refsource_CONFIRM
http://bugs.squid-cache.org/show_bug.cgi?id=3021
x_refsource_CONFIRM
http://bazaar.launchpad.net/~squid/squid/3.1/revision/10072
x_refsource_CONFIRM
http://bugs.gentoo.org/show_bug.cgi?id=334263
x_refsource_CONFIRM
http://www.squid-cache.org/Versions/v3/3.1/changesets/squid-3.1-10072.patch
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now