CVE-2011-3205

Buffer overflow in the gopherToHTML function in gopher.cc in the Gopher reply parser in Squid 3.0 before 3.0.STABLE26, 3.1 before 3.1.15, and 3.2 before 3.2.0.11 allows remote Gopher servers to cause a denial of service (memory corruption and daemon restart) or possibly have unspecified other impact via a long line in a response.  NOTE: This issue exists because of a CVE-2005-0094 regression.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
VendorProductVersion
squid-cachesquid
3.0.stable1:stable1
squid-cachesquid
3.0.stable2:stable2
squid-cachesquid
3.0.stable3:stable3
squid-cachesquid
3.0.stable4:stable4
squid-cachesquid
3.0.stable5:stable5
squid-cachesquid
3.0.stable6:stable6
squid-cachesquid
3.0.stable7:stable7
squid-cachesquid
3.0.stable8:stable8
squid-cachesquid
3.0.stable9:stable9
squid-cachesquid
3.0.stable10:stable10
squid-cachesquid
3.0.stable11:stable11
squid-cachesquid
3.0.stable11:stable11
squid-cachesquid
3.0.stable12:stable12
squid-cachesquid
3.0.stable13:stable13
squid-cachesquid
3.0.stable14:stable14
squid-cachesquid
3.0.stable15:stable15
squid-cachesquid
3.0.stable16:stable16
squid-cachesquid
3.0.stable16:stable16
squid-cachesquid
3.0.stable17:stable17
squid-cachesquid
3.0.stable18:stable18
squid-cachesquid
3.0.stable19:stable19
squid-cachesquid
3.0.stable20:stable20
squid-cachesquid
3.0.stable21:stable21
squid-cachesquid
3.0.stable22:stable22
squid-cachesquid
3.0.stable23:stable23
squid-cachesquid
3.0.stable24:stable24
squid-cachesquid
3.0.stable25:stable25
squid-cachesquid
3.1
squid-cachesquid
3.1.0.1
squid-cachesquid
3.1.0.2
squid-cachesquid
3.1.0.3
squid-cachesquid
3.1.0.4
squid-cachesquid
3.1.0.5
squid-cachesquid
3.1.0.6
squid-cachesquid
3.1.0.7
squid-cachesquid
3.1.0.8
squid-cachesquid
3.1.0.9
squid-cachesquid
3.1.0.10
squid-cachesquid
3.1.0.11
squid-cachesquid
3.1.0.12
squid-cachesquid
3.1.0.13
squid-cachesquid
3.1.0.14
squid-cachesquid
3.1.0.15
squid-cachesquid
3.1.0.16
squid-cachesquid
3.1.0.17
squid-cachesquid
3.1.0.18
squid-cachesquid
3.1.1
squid-cachesquid
3.1.2
squid-cachesquid
3.1.3
squid-cachesquid
3.1.4
squid-cachesquid
3.1.5
squid-cachesquid
3.1.5.1
squid-cachesquid
3.1.6
squid-cachesquid
3.1.7
squid-cachesquid
3.1.8
squid-cachesquid
3.1.9
squid-cachesquid
3.1.10
squid-cachesquid
3.1.11
squid-cachesquid
3.1.12
squid-cachesquid
3.1.13
squid-cachesquid
3.1.14
squid-cachesquid
3.2.0.1
squid-cachesquid
3.2.0.2
squid-cachesquid
3.2.0.3
squid-cachesquid
3.2.0.4
squid-cachesquid
3.2.0.5
squid-cachesquid
3.2.0.6
squid-cachesquid
3.2.0.7
squid-cachesquid
3.2.0.8
squid-cachesquid
3.2.0.9
squid-cachesquid
3.2.0.10
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
squid
bullseye (security)
4.13-10+deb11u3
fixed
bullseye
4.13-10+deb11u3
fixed
bookworm
5.7-2+deb12u2
fixed
bookworm (security)
5.7-2+deb12u2
fixed
sid
6.12-1
fixed
trixie
6.12-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
squid
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
not-affected
hardy
not-affected
squid3
oneiric
Fixed 3.1.14-1ubuntu0.1
released
natty
Fixed 3.1.11-1ubuntu0.1
released
maverick
Fixed 3.1.6-1.1ubuntu1.2
released
lucid
Fixed 3.0.STABLE19-1ubuntu0.2
released
hardy
ignored
References