Upstream information

CVE-2010-3072 at MITRE

Description

The string-comparison functions in String.cci in Squid 3.x before 3.1.8 and 3.2.x before 3.2.0.2 allow remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having moderate severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 5
Vector AV:N/AC:L/Au:N/C:N/I:N/A:P
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial
SUSE Bugzilla entry: 637287 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
openSUSE 11.1
  • squid3-debuginfo >= 3.0.STABLE10-2.14.1
  • squid3-debugsource >= 3.0.STABLE10-2.14.1
openSUSE 11.1
  • squid3 >= 3.0.STABLE10-2.14.1
openSUSE 11.2
  • squid3-debuginfo >= 3.0.STABLE18-3.6.1
  • squid3-debugsource >= 3.0.STABLE18-3.6.1
openSUSE 11.2
  • squid3 >= 3.0.STABLE18-3.6.1
openSUSE 11.3
  • squid3-debuginfo >= 3.0.STABLE25-2.1.1
  • squid3-debugsource >= 3.0.STABLE25-2.1.1
openSUSE 11.3
  • squid3 >= 3.0.STABLE25-2.1.1