CVE-2011-4096
Publication date 17 November 2011
Last updated 24 July 2024
Ubuntu priority
Description
The idnsGrokReply function in Squid before 3.1.16 does not properly free memory, which allows remote attackers to cause a denial of service (daemon abort) via a DNS reply containing a CNAME record that references another CNAME record that contains an empty A record.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| squid3 | ||
Patch details
| Package | Patch details |
|---|---|
| squid3 |