| MDVSA-2011:193: squid |
|
|
|
| Écrit par Administrator |
| Mercredi, 28 Décembre 2011 00:00 |
|
A vulnerability has been discovered and corrected in squid:
The idnsGrokReply function in Squid before 3.1.16 does not properly free memory, which allows remote attackers to cause a denial of service (daemon abort) via a DNS reply containing a CNAME record that references another CNAME record that contains an empty A record (CVE-2011-4096). The updated packages have been patched to correct this issue. |



























































