CVE-2010-2951

N/A Unknown
Published: October 12, 2010 Modified: April 29, 2026
View on NVD

Description

dns_internal.cc in Squid 3.1.6, when IPv6 DNS resolution is not enabled, accesses an invalid socket during an IPv4 TCP DNS query, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via vectors that trigger an IPv4 DNS response with the TC bit set.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://marc.info/?l=squid-users&m=128263555724981&w=2
Source: secalert@redhat.com
Patch Vendor Advisory
http://bazaar.launchpad.net/~squid/squid/3.1/revision/10072
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
http://bugs.gentoo.org/show_bug.cgi?id=334263
Source: af854a3a-2127-422b-91ae-364da2661108
http://bugs.squid-cache.org/show_bug.cgi?id=3009
Source: af854a3a-2127-422b-91ae-364da2661108
http://bugs.squid-cache.org/show_bug.cgi?id=3021
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=squid-users&m=128263555724981&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Vendor Advisory
http://www.openwall.com/lists/oss-security/2010/08/24/6
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.openwall.com/lists/oss-security/2010/08/24/7
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.openwall.com/lists/oss-security/2010/08/25/2
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
http://www.openwall.com/lists/oss-security/2010/08/25/6
Source: af854a3a-2127-422b-91ae-364da2661108
https://bugzilla.redhat.com/show_bug.cgi?id=626927
Source: af854a3a-2127-422b-91ae-364da2661108

22 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
31.5%
98th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

squid-cache