CVE-2013-4115: Opensuse

High severity, CVSS 7.5. EPSS: 43.9% chance of exploitation in the next 30 days.

Buffer overflow in the idnsALookup function in dns_internal.cc in Squid 3.2 through 3.2.11 and 3.3 through 3.3.6 allows remote attackers to cause a denial of service (memory corruption and server termination) via a long name in a DNS lookup request.

Affected products

  • Opensuse Opensuse: version 11.4 only; version 12.2 only; version 12.3 only
  • Squid-Cache Squid: version 3.2.0.2 only; version 3.2.0.3 only; version 3.2.0.4 only; version 3.2.0.5 only; version 3.2.0.6 only; version 3.2.0.7 only; …

Published 2013-08-09. Last modified 2026-06-16.