FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The last vuln.xml file processed by FreshPorts is:

Revision:  371804
Date:      2014-10-31
Time:      11:09:17Z
Committer: rea

List all Vulnerabilities, by package

List all Vulnerabilities, by date

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
c37de843-488e-11e2-a5c9-0019996bc1f7squid -- denial of service

Squid developers report:

Due to missing input validation Squid cachemgr.cgi tool is vulnerable to a denial of service attack when processing specially crafted requests.

This problem allows any client able to reach the cachemgr.cgi to perform a denial of service attack on the service host.

The nature of the attack may cause secondary effects through resource consumption on the host server.


Discovery 2012-12-17
Entry 2012-12-28
Modified 2013-05-02
squid
lt 2.7.9_4

ge 3.1 lt 3.1.23

ge 3.2 lt 3.2.6

ge 3.3 lt 3.3.0.3

CVE-2012-5643
CVE-2013-0189
http://www.squid-cache.org/Advisories/SQUID-2012_1.txt
e4dac715-c818-11df-a92c-0015587e2cc1squid -- Denial of service vulnerability in request handling

Squid security advisory 2010:3 reports:

Due to an internal error in string handling Squid is vulnerable to a denial of service attack when processing specially crafted requests.

This problem allows any trusted client to perform a denial of service attack on the Squid service.


Discovery 2010-08-30
Entry 2010-09-24
squid
ge 3.0.1 lt 3.0.25_3

ge 3.1.0.1 lt 3.1.8

CVE-2010-3072
http://www.squid-cache.org/Advisories/SQUID-2010_3.txt
296ecb59-0f6b-11df-8bab-0019996bc1f7squid -- Denial of Service vulnerability in DNS handling

Squid security advisory 2010:1 reports:

Due to incorrect data validation Squid is vulnerable to a denial of service attack when processing specially crafted DNS packets.

This problem allows any trusted client or external server who can determine the squid receiving port to perform a short-term denial of service attack on the Squid service.


Discovery 2010-01-14
Entry 2010-02-01
Modified 2010-05-02
squid
ge 2.7.1 lt 2.7.7_3

ge 3.0.1 lt 3.0.23

ge 3.1.0.1 lt 3.1.0.15_2

CVE-2010-0308
http://www.squid-cache.org/Advisories/SQUID-2010_1.txt
e4dac715-c818-11df-a92c-0015587e2cc1squid -- Denial of service vulnerability in request handling

Squid security advisory 2010:3 reports:

Due to an internal error in string handling Squid is vulnerable to a denial of service attack when processing specially crafted requests.

This problem allows any trusted client to perform a denial of service attack on the Squid service.


Discovery 2010-08-30
Entry 2010-09-24
squid
ge 3.0.1 lt 3.0.25_3

ge 3.1.0.1 lt 3.1.8

CVE-2010-3072
http://www.squid-cache.org/Advisories/SQUID-2010_3.txt
296ecb59-0f6b-11df-8bab-0019996bc1f7squid -- Denial of Service vulnerability in DNS handling

Squid security advisory 2010:1 reports:

Due to incorrect data validation Squid is vulnerable to a denial of service attack when processing specially crafted DNS packets.

This problem allows any trusted client or external server who can determine the squid receiving port to perform a short-term denial of service attack on the Squid service.


Discovery 2010-01-14
Entry 2010-02-01
Modified 2010-05-02
squid
ge 2.7.1 lt 2.7.7_3

ge 3.0.1 lt 3.0.23

ge 3.1.0.1 lt 3.1.0.15_2

CVE-2010-0308
http://www.squid-cache.org/Advisories/SQUID-2010_1.txt