CVE-2011-4096

Squid < 3.1.16 - Denial of Service via DNS CNAME Record Handling

Title source: llm
STIX 2.1

Description

The idnsGrokReply function in Squid before 3.1.16 does not properly free memory, which allows remote attackers to cause a denial of service (daemon abort) via a DNS reply containing a CNAME record that references another CNAME record that contains an empty A record.

References (11)

Core 11
Core References
Various Sources x_refsource_misc
http://bugs.squid-cache.org/show_bug.cgi?id=3237#c12
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2011-1791.html
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/10/31/5
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1026265
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/11/01/3
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2011:193
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/46609
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/47459

Scores

EPSS 0.3719
EPSS Percentile 98.3%

Details

CWE
CWE-399
Status published
Products (24)
squid-cache/squid 3.0 (25 CPE variants)
squid-cache/squid 3.0.stable1
squid-cache/squid 3.0.stable2
squid-cache/squid 3.0.stable3
squid-cache/squid 3.0.stable4
squid-cache/squid 3.0.stable5
squid-cache/squid 3.0.stable6
squid-cache/squid 3.0.stable7
squid-cache/squid 3.0.stable8
squid-cache/squid 3.0.stable9
... and 14 more
Published Nov 17, 2011
Tracked Since Feb 18, 2026