← All CVEs

CVE-2011-3205

medium · 6.8

Buffer overflow in the gopherToHTML function in gopher.cc in the Gopher reply parser in Squid 3.0 before 3.0.STABLE26, 3.1 before 3.1.15, and 3.2 before 3.2.0.11 allows remote Gopher servers to cause a denial of service (memory corruption and daemon restart) or possibly have unspecified other impact via a long line in a response. NOTE: This issue exists because of a CVE-2005-0094 regression.

6.8
CVSS
27.5%
EPSS (exploit prob.)
98th
EPSS percentile
2011-09-06
Published

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

VendorProductAffected versions
squid-cachesquid3.0.stable1
squid-cachesquid3.0.stable2
squid-cachesquid3.0.stable3
squid-cachesquid3.0.stable4
squid-cachesquid3.0.stable5
squid-cachesquid3.0.stable6
squid-cachesquid3.0.stable7
squid-cachesquid3.0.stable8
squid-cachesquid3.0.stable9
squid-cachesquid3.0.stable10
squid-cachesquid3.0.stable11
squid-cachesquid3.0.stable11
squid-cachesquid3.0.stable12
squid-cachesquid3.0.stable13
squid-cachesquid3.0.stable14
squid-cachesquid3.0.stable15
squid-cachesquid3.0.stable16
squid-cachesquid3.0.stable16
squid-cachesquid3.0.stable17
squid-cachesquid3.0.stable18
squid-cachesquid3.0.stable19
squid-cachesquid3.0.stable20
squid-cachesquid3.0.stable21
squid-cachesquid3.0.stable22
squid-cachesquid3.0.stable23
squid-cachesquid3.0.stable24
squid-cachesquid3.0.stable25
squid-cachesquid3.1
squid-cachesquid3.1.0.1
squid-cachesquid3.1.0.2
squid-cachesquid3.1.0.3
squid-cachesquid3.1.0.4
squid-cachesquid3.1.0.5
squid-cachesquid3.1.0.6
squid-cachesquid3.1.0.7
squid-cachesquid3.1.0.8
squid-cachesquid3.1.0.9
squid-cachesquid3.1.0.10
squid-cachesquid3.1.0.11
squid-cachesquid3.1.0.12

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2011-3205