CVE-2010-2951

NameCVE-2010-2951
Descriptiondns_internal.cc in Squid 3.1.6, when IPv6 DNS resolution is not enabled, accesses an invalid socket during an IPv4 TCP DNS query, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via vectors that trigger an IPv4 DNS response with the TC bit set.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium (attack range: remote)
Debian Bugs599709

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
squid3 (PTS)jessie3.4.8-6+deb8u5fixed
jessie (security)3.4.8-6+deb8u6fixed
stretch (security), stretch3.5.23-5+deb9u1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
squid3source(unstable)3.1.6-1.2medium599709
squid3sourcelenny(not affected)

Notes

[lenny] - squid3 <not-affected> (vulnerable code introduced in 3.1.6)
http://marc.info/?l=squid-users&m=128263555724981&w=2

Search for package or bug name: Reporting problems