This application requires Javascript for optimal performance.

Squid.DNS.Replies.Invalid.Free.DoS

Release Date

Nov 16, 2011

Severity

medium

Impact

Denial of Service: Remote attackers can crash vulnerable systems.

Description

This indicates an attack attempt to exploit a Denial of Service vulnerability in Squid.

The vulnerability results from an error when the vulnerable software handles certain DNS replies. A remote attacker may exploit this to terminate the target server, creating a denial of service condition .

Affected Products

Squid Project Squid prior to 3.1.16

Recommended Actions

Apply patches or fixes from the vendor, available from the website:
http://bugs.squid-cache.org/show_bug.cgi?id=3237

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2011-4096

Reference/s

https://portal.telussecuritylabs.com/threat/TSL20111101-03

Reference: VID-30007