CVE-2011-3205
medium · 6.8Buffer overflow in the gopherToHTML function in gopher.cc in the Gopher reply parser in Squid 3.0 before 3.0.STABLE26, 3.1 before 3.1.15, and 3.2 before 3.2.0.11 allows remote Gopher servers to cause a denial of service (memory corruption and daemon restart) or possibly have unspecified other impact via a long line in a response. NOTE: This issue exists because of a CVE-2005-0094 regression.
6.8
CVSS
27.5%
EPSS (exploit prob.)
98th
EPSS percentile
2011-09-06
Published
AV:N/AC:M/Au:N/C:P/I:P/A:P
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| squid-cache | squid | 3.0.stable1 |
| squid-cache | squid | 3.0.stable2 |
| squid-cache | squid | 3.0.stable3 |
| squid-cache | squid | 3.0.stable4 |
| squid-cache | squid | 3.0.stable5 |
| squid-cache | squid | 3.0.stable6 |
| squid-cache | squid | 3.0.stable7 |
| squid-cache | squid | 3.0.stable8 |
| squid-cache | squid | 3.0.stable9 |
| squid-cache | squid | 3.0.stable10 |
| squid-cache | squid | 3.0.stable11 |
| squid-cache | squid | 3.0.stable11 |
| squid-cache | squid | 3.0.stable12 |
| squid-cache | squid | 3.0.stable13 |
| squid-cache | squid | 3.0.stable14 |
| squid-cache | squid | 3.0.stable15 |
| squid-cache | squid | 3.0.stable16 |
| squid-cache | squid | 3.0.stable16 |
| squid-cache | squid | 3.0.stable17 |
| squid-cache | squid | 3.0.stable18 |
| squid-cache | squid | 3.0.stable19 |
| squid-cache | squid | 3.0.stable20 |
| squid-cache | squid | 3.0.stable21 |
| squid-cache | squid | 3.0.stable22 |
| squid-cache | squid | 3.0.stable23 |
| squid-cache | squid | 3.0.stable24 |
| squid-cache | squid | 3.0.stable25 |
| squid-cache | squid | 3.1 |
| squid-cache | squid | 3.1.0.1 |
| squid-cache | squid | 3.1.0.2 |
| squid-cache | squid | 3.1.0.3 |
| squid-cache | squid | 3.1.0.4 |
| squid-cache | squid | 3.1.0.5 |
| squid-cache | squid | 3.1.0.6 |
| squid-cache | squid | 3.1.0.7 |
| squid-cache | squid | 3.1.0.8 |
| squid-cache | squid | 3.1.0.9 |
| squid-cache | squid | 3.1.0.10 |
| squid-cache | squid | 3.1.0.11 |
| squid-cache | squid | 3.1.0.12 |
Check a specific version with /api/v1/cve/match.
References
- http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065534.html
- http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00012.html
- http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00013.html
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00040.html
- http://openwall.com/lists/oss-security/2011/08/29/2
- http://openwall.com/lists/oss-security/2011/08/30/4
- http://openwall.com/lists/oss-security/2011/08/30/8
- http://secunia.com/advisories/45805
- http://secunia.com/advisories/45906
- http://secunia.com/advisories/45920
- http://secunia.com/advisories/45965
- http://secunia.com/advisories/46029
- http://securitytracker.com/id?1025981
- http://www.debian.org/security/2011/dsa-2304
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:150
- http://www.osvdb.org/74847
- http://www.redhat.com/support/errata/RHSA-2011-1293.html
- http://www.securityfocus.com/bid/49356
- http://www.squid-cache.org/Advisories/SQUID-2011_3.txt
- http://www.squid-cache.org/Versions/v2/2.HEAD/changesets/12710.patch
- http://www.squid-cache.org/Versions/v3/3.0/changesets/squid-3.0-9193.patch
- http://www.squid-cache.org/Versions/v3/3.1/changesets/squid-3.1-10363.patch
- http://www.squid-cache.org/Versions/v3/3.2/changesets/squid-3.2-11294.patch
- https://bugzilla.redhat.com/show_bug.cgi?id=734583
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2011-3205