CVE-2013-4115

high
Published 2013-08-09 · Modified 2026-04-29
CVSS v3
CVSS v2
7.5
VIR risk
7.5

Description

Buffer overflow in the idnsALookup function in dns_internal.cc in Squid 3.2 through 3.2.11 and 3.3 through 3.3.6 allows remote attackers to cause a denial of service (memory corruption and server termination) via a long name in a DNS lookup request.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2013-4115

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.squid-cache.org/Versions/v3/3.3/changesets/squid-3.3-12587.patch

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.squid-cache.org/Versions/v3/3.2/changesets/squid-3.2-11823.patch

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.squid-cache.org/Versions/v3/3.1/changesets/squid-3.1-10487.patch

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.squid-cache.org/Versions/v3/3.0/changesets/squid-3.0-9200.patch

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.squid-cache.org/Advisories/SQUID-2013_2.txt

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/54839

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/54834

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/54076

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://lists.opensuse.org/opensuse-updates/2013-09/msg00033.html

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://lists.opensuse.org/opensuse-updates/2013-09/msg00032.html

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://lists.opensuse.org/opensuse-updates/2013-09/msg00030.html

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://lists.opensuse.org/opensuse-updates/2013-09/msg00025.html

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://lists.opensuse.org/opensuse-updates/2013-09/msg00024.html

OS impact

OSVersionStatusFixed in
suse suse11.4affected
suse suse12.2affected
suse suse12.3affected
debian debianbookwormfixed0
debian debianbullseyefixed0
debian debianforkyfixed0
debian debiansidfixed0
debian debiantrixiefixed0

Application impact

VendorProductVersionsFixed
squid-cachesquid3.2.0.1
squid-cachesquid3.2.0.2
squid-cachesquid3.2.0.3
squid-cachesquid3.2.0.4
squid-cachesquid3.2.0.5
squid-cachesquid3.2.0.6
squid-cachesquid3.2.0.7
squid-cachesquid3.2.0.8
squid-cachesquid3.2.0.9
squid-cachesquid3.2.0.10
squid-cachesquid3.2.0.11
squid-cachesquid3.3.0
squid-cachesquid3.3.0.2
squid-cachesquid3.3.0.3
squid-cachesquid3.3.1
squid-cachesquid3.3.2
squid-cachesquid3.3.3
squid-cachesquid3.3.4
squid-cachesquid3.3.5
squid-cachesquid3.3.6

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.