First published: Tue Aug 30 2011(Updated: )
A flaw was reported [1] in how Squid parsed responses from Gopher servers. This flaw could result in a buffer overflow if a Gopher server were to return a line longer than 4096 bytes, leading to memory corruption and a crash. This flaw is an extension of SQUID-2005:1 (or <a href="https://access.redhat.com/security/cve/CVE-2005-0094">CVE-2005-0094</a>) in Squid 3.x, due to increased packet read sizes. A malicious user could setup a fake Gopher server and forward requests to it through Squid. A specially crafted response from that server could cause Squid to restart. This has been corrected in upstream versions 3.2.0.11, 3.1.15, and 3.0.STABLE26. Patches for 3.0 [2], 3.1 [3], and 3.2 [4] are available. [1] <a href="http://www.squid-cache.org/Advisories/SQUID-2011_3.txt">http://www.squid-cache.org/Advisories/SQUID-2011_3.txt</a> [2] <a href="http://www.squid-cache.org/Versions/v3/3.0/changesets/squid-3.0-9193.patch">http://www.squid-cache.org/Versions/v3/3.0/changesets/squid-3.0-9193.patch</a> [3] <a href="http://www.squid-cache.org/Versions/v3/3.1/changesets/squid-3.1-10363.patch">http://www.squid-cache.org/Versions/v3/3.1/changesets/squid-3.1-10363.patch</a> [4] <a href="http://www.squid-cache.org/Versions/v3/3.2/changesets/squid-3.2-11294.patch">http://www.squid-cache.org/Versions/v3/3.2/changesets/squid-3.2-11294.patch</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Squid Web Proxy Cache | =3.0.stable1 | |
Squid Web Proxy Cache | =3.0.stable2 | |
Squid Web Proxy Cache | =3.0.stable3 | |
Squid Web Proxy Cache | =3.0.stable4 | |
Squid Web Proxy Cache | =3.0.stable5 | |
Squid Web Proxy Cache | =3.0.stable6 | |
Squid Web Proxy Cache | =3.0.stable7 | |
Squid Web Proxy Cache | =3.0.stable8 | |
Squid Web Proxy Cache | =3.0.stable9 | |
Squid Web Proxy Cache | =3.0.stable10 | |
Squid Web Proxy Cache | =3.0.stable11 | |
Squid Web Proxy Cache | =3.0.stable11-rc1 | |
Squid Web Proxy Cache | =3.0.stable12 | |
Squid Web Proxy Cache | =3.0.stable13 | |
Squid Web Proxy Cache | =3.0.stable14 | |
Squid Web Proxy Cache | =3.0.stable15 | |
Squid Web Proxy Cache | =3.0.stable16 | |
Squid Web Proxy Cache | =3.0.stable16-rc1 | |
Squid Web Proxy Cache | =3.0.stable17 | |
Squid Web Proxy Cache | =3.0.stable18 | |
Squid Web Proxy Cache | =3.0.stable19 | |
Squid Web Proxy Cache | =3.0.stable20 | |
Squid Web Proxy Cache | =3.0.stable21 | |
Squid Web Proxy Cache | =3.0.stable22 | |
Squid Web Proxy Cache | =3.0.stable23 | |
Squid Web Proxy Cache | =3.0.stable24 | |
Squid Web Proxy Cache | =3.0.stable25 | |
Squid Web Proxy Cache | =3.1 | |
Squid Web Proxy Cache | =3.1.0.1 | |
Squid Web Proxy Cache | =3.1.0.2 | |
Squid Web Proxy Cache | =3.1.0.3 | |
Squid Web Proxy Cache | =3.1.0.4 | |
Squid Web Proxy Cache | =3.1.0.5 | |
Squid Web Proxy Cache | =3.1.0.6 | |
Squid Web Proxy Cache | =3.1.0.7 | |
Squid Web Proxy Cache | =3.1.0.8 | |
Squid Web Proxy Cache | =3.1.0.9 | |
Squid Web Proxy Cache | =3.1.0.10 | |
Squid Web Proxy Cache | =3.1.0.11 | |
Squid Web Proxy Cache | =3.1.0.12 | |
Squid Web Proxy Cache | =3.1.0.13 | |
Squid Web Proxy Cache | =3.1.0.14 | |
Squid Web Proxy Cache | =3.1.0.15 | |
Squid Web Proxy Cache | =3.1.0.16 | |
Squid Web Proxy Cache | =3.1.0.17 | |
Squid Web Proxy Cache | =3.1.0.18 | |
Squid Web Proxy Cache | =3.1.1 | |
Squid Web Proxy Cache | =3.1.2 | |
Squid Web Proxy Cache | =3.1.3 | |
Squid Web Proxy Cache | =3.1.4 | |
Squid Web Proxy Cache | =3.1.5 | |
Squid Web Proxy Cache | =3.1.5.1 | |
Squid Web Proxy Cache | =3.1.6 | |
Squid Web Proxy Cache | =3.1.7 | |
Squid Web Proxy Cache | =3.1.8 | |
Squid Web Proxy Cache | =3.1.9 | |
Squid Web Proxy Cache | =3.1.10 | |
Squid Web Proxy Cache | =3.1.11 | |
Squid Web Proxy Cache | =3.1.12 | |
Squid Web Proxy Cache | =3.1.13 | |
Squid Web Proxy Cache | =3.1.14 | |
Squid Web Proxy Cache | =3.2.0.1 | |
Squid Web Proxy Cache | =3.2.0.2 | |
Squid Web Proxy Cache | =3.2.0.3 | |
Squid Web Proxy Cache | =3.2.0.4 | |
Squid Web Proxy Cache | =3.2.0.5 | |
Squid Web Proxy Cache | =3.2.0.6 | |
Squid Web Proxy Cache | =3.2.0.7 | |
Squid Web Proxy Cache | =3.2.0.8 | |
Squid Web Proxy Cache | =3.2.0.9 | |
Squid Web Proxy Cache | =3.2.0.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-3205 has a high severity due to potential buffer overflow leading to memory corruption and crashes.
CVE-2011-3205 affects multiple versions of Squid including 3.0.stable1 through 3.0.stable24 and several 3.1.x versions.
To fix CVE-2011-3205, upgrade to a version of Squid that is not affected by this vulnerability.
CVE-2011-3205 is a buffer overflow vulnerability affecting Squid proxy server's handling of Gopher responses.
The potential impacts of CVE-2011-3205 include crashes of the Squid service and possible exploitation leading to arbitrary code execution.