Description
The idnsGrokReply function in Squid before 3.1.16 does not properly free memory, which allows remote attackers to cause a denial of service (daemon abort) via a DNS reply containing a CNAME record that references another CNAME record that contains an empty A record.
Remediation
References
Related Vulnerabilities
Serendipity Other Vulnerability (CVE-2004-1620)
WordPress Plugin Deny All Firewall Cross-Site Request Forgery (1.1.6)
WordPress Plugin Restaurant Menu-Food Ordering System-Table Reservation Security Bypass (2.3.0)
Oracle HTTP Server Other Vulnerability (CVE-2002-0656)
WordPress Plugin Visual CSS Style Editor Cross-Site Request Forgery (7.2.0)