CVE-2011-3205
Summary
| CVE | CVE-2011-3205 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-09-06 15:55:08 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Buffer overflow in the gopherToHTML function in gopher.cc in the Gopher reply parser in Squid 3.0 before 3.0.STABLE26, 3.1 before 3.1.15, and 3.2 before 3.2.0.11 allows remote Gopher servers to cause a denial of service (memory corruption and daemon restart) or possibly have unspecified other impact via a long line in a response. NOTE: This issue exists because of a CVE-2005-0094 regression. |
Risk And Classification
Primary CVSS: v2.0 6.8 from [email protected]
AV:N/AC:M/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Squid-cache | Squid | 3.0.stable1 | All | All | All |
| Application | Squid-cache | Squid | 3.0.stable10 | All | All | All |
| Application | Squid-cache | Squid | 3.0.stable11 | All | All | All |
| Application | Squid-cache | Squid | 3.0.stable11 | rc1 | All | All |
| Application | Squid-cache | Squid | 3.0.stable12 | All | All | All |
| Application | Squid-cache | Squid | 3.0.stable13 | All | All | All |
| Application | Squid-cache | Squid | 3.0.stable14 | All | All | All |
| Application | Squid-cache | Squid | 3.0.stable15 | All | All | All |
| Application | Squid-cache | Squid | 3.0.stable16 | All | All | All |
| Application | Squid-cache | Squid | 3.0.stable16 | rc1 | All | All |
| Application | Squid-cache | Squid | 3.0.stable17 | All | All | All |
| Application | Squid-cache | Squid | 3.0.stable18 | All | All | All |
| Application | Squid-cache | Squid | 3.0.stable19 | All | All | All |
| Application | Squid-cache | Squid | 3.0.stable2 | All | All | All |
| Application | Squid-cache | Squid | 3.0.stable20 | All | All | All |
| Application | Squid-cache | Squid | 3.0.stable21 | All | All | All |
| Application | Squid-cache | Squid | 3.0.stable22 | All | All | All |
| Application | Squid-cache | Squid | 3.0.stable23 | All | All | All |
| Application | Squid-cache | Squid | 3.0.stable24 | All | All | All |
| Application | Squid-cache | Squid | 3.0.stable25 | All | All | All |
| Application | Squid-cache | Squid | 3.0.stable3 | All | All | All |
| Application | Squid-cache | Squid | 3.0.stable4 | All | All | All |
| Application | Squid-cache | Squid | 3.0.stable5 | All | All | All |
| Application | Squid-cache | Squid | 3.0.stable6 | All | All | All |
| Application | Squid-cache | Squid | 3.0.stable7 | All | All | All |
| Application | Squid-cache | Squid | 3.0.stable8 | All | All | All |
| Application | Squid-cache | Squid | 3.0.stable9 | All | All | All |
| Application | Squid-cache | Squid | 3.1 | All | All | All |
| Application | Squid-cache | Squid | 3.1.0.1 | All | All | All |
| Application | Squid-cache | Squid | 3.1.0.10 | All | All | All |
| Application | Squid-cache | Squid | 3.1.0.11 | All | All | All |
| Application | Squid-cache | Squid | 3.1.0.12 | All | All | All |
| Application | Squid-cache | Squid | 3.1.0.13 | All | All | All |
| Application | Squid-cache | Squid | 3.1.0.14 | All | All | All |
| Application | Squid-cache | Squid | 3.1.0.15 | All | All | All |
| Application | Squid-cache | Squid | 3.1.0.16 | All | All | All |
| Application | Squid-cache | Squid | 3.1.0.17 | All | All | All |
| Application | Squid-cache | Squid | 3.1.0.18 | All | All | All |
| Application | Squid-cache | Squid | 3.1.0.2 | All | All | All |
| Application | Squid-cache | Squid | 3.1.0.3 | All | All | All |
| Application | Squid-cache | Squid | 3.1.0.4 | All | All | All |
| Application | Squid-cache | Squid | 3.1.0.5 | All | All | All |
| Application | Squid-cache | Squid | 3.1.0.6 | All | All | All |
| Application | Squid-cache | Squid | 3.1.0.7 | All | All | All |
| Application | Squid-cache | Squid | 3.1.0.8 | All | All | All |
| Application | Squid-cache | Squid | 3.1.0.9 | All | All | All |
| Application | Squid-cache | Squid | 3.1.1 | All | All | All |
| Application | Squid-cache | Squid | 3.1.10 | All | All | All |
| Application | Squid-cache | Squid | 3.1.11 | All | All | All |
| Application | Squid-cache | Squid | 3.1.12 | All | All | All |
| Application | Squid-cache | Squid | 3.1.13 | All | All | All |
| Application | Squid-cache | Squid | 3.1.14 | All | All | All |
| Application | Squid-cache | Squid | 3.1.2 | All | All | All |
| Application | Squid-cache | Squid | 3.1.3 | All | All | All |
| Application | Squid-cache | Squid | 3.1.4 | All | All | All |
| Application | Squid-cache | Squid | 3.1.5 | All | All | All |
| Application | Squid-cache | Squid | 3.1.5.1 | All | All | All |
| Application | Squid-cache | Squid | 3.1.6 | All | All | All |
| Application | Squid-cache | Squid | 3.1.7 | All | All | All |
| Application | Squid-cache | Squid | 3.1.8 | All | All | All |
| Application | Squid-cache | Squid | 3.1.9 | All | All | All |
| Application | Squid-cache | Squid | 3.2.0.1 | All | All | All |
| Application | Squid-cache | Squid | 3.2.0.10 | All | All | All |
| Application | Squid-cache | Squid | 3.2.0.2 | All | All | All |
| Application | Squid-cache | Squid | 3.2.0.3 | All | All | All |
| Application | Squid-cache | Squid | 3.2.0.4 | All | All | All |
| Application | Squid-cache | Squid | 3.2.0.5 | All | All | All |
| Application | Squid-cache | Squid | 3.2.0.6 | All | All | All |
| Application | Squid-cache | Squid | 3.2.0.7 | All | All | All |
| Application | Squid-cache | Squid | 3.2.0.8 | All | All | All |
| Application | Squid-cache | Squid | 3.2.0.9 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.squid-cache.org/Versions/v3/3.0/changesets/squid-3.0-9193.patch | af854a3a-2127-422b-91ae-364da2661108 | www.squid-cache.org | Patch |
| [SECURITY] Fedora 14 Update: squid-3.1.15-1.fc14 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| Debian update for squid3 - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Bug 734583 – CVE-2011-3205 squid: buffer overflow flaw in Squid's Gopher reply parser (SQUID-2011:3) | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Patch |
| Squid Proxy Gopher Remote Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| oss-security - CVE-request(?): squid: buffer overflow in Gopher reply parser | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | |
| Support / Security / Advisories / / MDVSA-2011:150 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| www.osvdb.org/74847 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| www.squid-cache.org/Versions/v3/3.1/changesets/squid-3.1-10363.patch | af854a3a-2127-422b-91ae-364da2661108 | www.squid-cache.org | Patch |
| SecurityTracker: Squid Gopher Response Memory Corruption Error Lets Remote Users Deny Service | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Fedora update for squid - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| www.squid-cache.org/Advisories/SQUID-2011_3.txt | af854a3a-2127-422b-91ae-364da2661108 | www.squid-cache.org | |
| [security-announce] SUSE-SU-2011:1019-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Debian -- Security Information -- DSA-2304-1 squid3 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| [security-announce] openSUSE-SU-2011:1018-1: important: VUL-0: CVE-2011- | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| oss-security - Re: CVE-request(?): squid: buffer overflow in Gopher reply parser | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | |
| SUSE update for squid3 - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| www.squid-cache.org/Versions/v2/2.HEAD/changesets/12710.patch | af854a3a-2127-422b-91ae-364da2661108 | www.squid-cache.org | Patch |
| www.squid-cache.org/Versions/v3/3.2/changesets/squid-3.2-11294.patch | af854a3a-2127-422b-91ae-364da2661108 | www.squid-cache.org | Patch |
| [security-announce] SUSE-SU-2016:1996-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| oss-security - Re: CVE-request(?): squid: buffer overflow in Gopher reply parser | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | |
| [security-announce] SUSE-SU-2016:2089-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Red Hat update for squid - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.