CVE-2011-3205 is a buffer overflow vulnerability in the gopherToHTML function of the Squid proxy server, affecting versions 3.0 before 3.0.STABLE26, 3.1 before 3.1.15, and 3.2 before 3.2.0.11. A remote Gopher server can exploit this by sending a long line in a response, leading to a denial of service (memory corruption and daemon restart) or potentially other unspecified impacts. With a CVSS score of 6.8 (medium severity), it has a high EPSS score of 0.74962, indicating a higher-than-average probability of exploitation. Despite this, there is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0.stable1CPE matchmatch criteria | cpe:2.3:a:squid-cache:squid:3.0.stable1:*:*:*:*:*:*:* | ||
3.0.stable2CPE matchmatch criteria | cpe:2.3:a:squid-cache:squid:3.0.stable2:*:*:*:*:*:*:* | ||
3.0.stable3CPE matchmatch criteria | cpe:2.3:a:squid-cache:squid:3.0.stable3:*:*:*:*:*:*:* | ||
3.0.stable4CPE matchmatch criteria | cpe:2.3:a:squid-cache:squid:3.0.stable4:*:*:*:*:*:*:* | ||
3.0.stable5CPE matchmatch criteria | cpe:2.3:a:squid-cache:squid:3.0.stable5:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.