Description
lib/rfc1035.c in Squid 2.x, 3.0 through 3.0.STABLE22, and 3.1 through 3.1.0.15 allows remote attackers to cause a denial of service (assertion failure) via a crafted DNS packet that only contains a header.
CVSS vector
AV:N/AC:L/C:N/I:N/A:PExploitability: 8.0 | Impact: 2.9Complexity: Low
Confidentiality: None
Integrity: None
Affected Packages2 packages
🔴Vulnerability Details
3GHSAGHSA-wg6g-7g6h-p73r: lib/rfc1035↗2022-05-02 ▶ OSVCVE-2010-0308: lib/rfc1035↗2010-02-03 ▶ CVEListCVE-2010-0308: lib/rfc1035↗2010-02-03 ▶ 💥Exploits & PoCs
1Exploit-DBURSoft W32Dasm 8.93 - Disassembler Function Buffer Overflow (Metasploit)↗2010-09-25 ▶ 📋Vendor Advisories
3UbuntuSquid vulnerabilities↗2010-02-16 ▶ DebianCVE-2010-0308: squid - lib/rfc1035.c in Squid 2.x, 3.0 through 3.0.STABLE22, and 3.1 through 3.1.0.15 a...↗2010 ▶ Red Hatsquid: temporary DoS (assertion failure) triggered by truncated DNS packet (SQUID-2010:1)↗2009-12-27 ▶ 💬Community
2BugzillaCVE-2010-0308 squid: temporary DoS (assertion failure) triggered by truncated DNS packet (SQUID-2010:1) [Fedora all]↗2010-02-04 ▶ BugzillaCVE-2010-0308 squid: temporary DoS (assertion failure) triggered by truncated DNS packet (SQUID-2010:1)↗2010-01-18 ▶