VDB
CVE-2011-3205
CVE-2011-3205
PUBLISHED
CVSS 6.800000190734863 MEDIUM
Buffer overflow in the gopherToHTML function in gopher.cc in the Gopher reply parser in Squid 3.0 before 3.0.STABLE26, 3.1 before 3.1.15, and 3.2 before 3.2.0.11 allows remote Gopher servers to cause a denial of service (memory corruption and daemon restart) or possibly have unspecified other impact via a long line in a response. NOTE: This issue exists because of a CVE-2005-0094 regression.
EPSS 27.45% · 98.0th percentile
Risk Scores
CVSS 2.0
6.800000190734863
EPSS Score
27.45%
98.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a, n/a, n/a |
| squid-cache | squid | 3.0.stable1, 3.0.stable2, 3.0.stable3 |
Timeline
- Sep 6, 2011 CVE Published
- Feb 4, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Dec 22, 2023 EPSS Score
- Feb 13, 2024 EPSS Score
References
- http://www.osvdb.org/74847 url
- http://secunia.com/advisories/46029 technical
- http://www.redhat.com/support/errata/RHSA-2011-1293.html technical
- http://openwall.com/lists/oss-security/2011/08/29/2 technical
- https://bugzilla.redhat.com/show_bug.cgi?id=734583 url
- http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00013.html url
- http://www.squid-cache.org/Advisories/SQUID-2011_3.txt technical
- http://openwall.com/lists/oss-security/2011/08/30/4 url
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:150 url
- http://www.squid-cache.org/Versions/v2/2.HEAD/changesets/12710.patch url
- http://www.squid-cache.org/Versions/v3/3.0/changesets/squid-3.0-9193.patch patch
- SUSE-SU-2016:1996 vendor-advisory
- 45805 third-party-advisory
- 45920 third-party-advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00040.html url
- http://www.squid-cache.org/Versions/v3/3.2/changesets/squid-3.2-11294.patch url
- http://securitytracker.com/id?1025981 technical
- http://www.squid-cache.org/Versions/v3/3.1/changesets/squid-3.1-10363.patch patch
- http://secunia.com/advisories/45965 technical
- [oss-security] 20110830 Re: CVE-request(?): squid: buffer overflow in Gopher reply parser mailing-list
…and 6 more