CVE-2010-3072Squid vulnerability

7 documents6 sources
Severity
5.0MEDIUMNVD
EPSS
72.5%
top 1.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 20
Latest updateMay 17

Description

The string-comparison functions in String.cci in Squid 3.x before 3.1.8 and 3.2.x before 3.2.0.2 allow remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDsquid-cache/squid53 versions+52

Patches

🔴Vulnerability Details

2
GHSA
GHSA-744h-wcjj-gwrf: The string-comparison functions in String2022-05-17
CVEList
CVE-2010-3072: The string-comparison functions in String2010-09-20

📋Vendor Advisories

2
Red Hat
Squid: Denial of service due internal error in string handling (SQUID-2010:3)2010-09-03
Debian
CVE-2010-3072: squid - The string-comparison functions in String.cci in Squid 3.x before 3.1.8 and 3.2....2010

💬Community

2
Bugzilla
CVE-2010-3072 Squid: Denial of service due internal error in string handling (SQUID-2010:3)2010-09-05
Bugzilla
CVE-2010-3072 Squid: Denial of service due internal error in string handling (SQUID-2010:3) [fedora-all]2010-09-05
CVE-2010-3072 — Squid-cache Squid vulnerability | cvebase