Giuseppe Iuculano
2010-Mar-28 21:24 UTC
[Secure-testing-team] Bug#575747: CVE-2010-0308: denial of service via a crafted DNS packet
Package: squid3 Severity: serious Tags: security -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for squid3. CVE-2010-0308[0]: | lib/rfc1035.c in Squid 2.x, 3.0 through 3.0.STABLE22, and 3.1 through | 3.1.0.15 allows remote attackers to cause a denial of service | (assertion failure) via a crafted DNS packet that only contains a | header. If you fix the vulnerability please also make sure to include the CVE id in your changelog entry. For further information see: [0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0308 http://security-tracker.debian.org/tracker/CVE-2010-0308 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAkuvyQ4ACgkQNxpp46476arqKgCfV9CtK4geHcTUyTO1jMM3b9Uq PicAn2y+7V71eqNeYxlnd83JixlAt0zY =Mtru -----END PGP SIGNATURE-----