Squid 3.1.6 DNS Reply Denial of Service

This script is Copyright (C) 2010-2014 Tenable Network Security, Inc.


Synopsis :

The remote proxy server is affected by a denial of service
vulnerability.

Description :

According to its banner, the version of the Squid proxy caching server
installed on the remote host is 3.1.6. This version is affected by a
denial of service vulnerability that is caused by an assertion failure
when contacting IPv4-only DNS resolvers.

Note that Nessus has relied only on the version in the proxy server's
banner, which is not updated by either of the patches the project has
released to address this issue. If one of those has been applied
properly and the service restarted, consider this to be a false
positive.

See also :

http://bugs.squid-cache.org/show_bug.cgi?id=3021
http://www.squid-cache.org/mail-archive/squid-users/201008/0480.html

Solution :

Upgrade to Squid version 3.1.7 or later

Risk factor :

Medium / CVSS Base Score : 4.3
(CVSS2#AV:N/AC:M/Au:N/C:N/I:N/A:P)
CVSS Temporal Score : 3.2
(CVSS2#E:U/RL:OF/RC:C)
Public Exploit Available : false

Family: Firewalls

Nessus Plugin ID: 48433 ()

Bugtraq ID: 42645

CVE ID: CVE-2010-2951