---
title: "CVE-2011-3205\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2011-3205?format=md
keywords: index, follow
---

# CVE-2011-3205

Publication date 6 September 2011

Last updated 4 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Buffer overflow in the gopherToHTML function in gopher.cc in the Gopher
reply parser in Squid 3.0 before 3.0.STABLE26, 3.1 before 3.1.15, and 3.2
before 3.2.0.11 allows remote Gopher servers to cause a denial of service
(memory corruption and daemon restart) or possibly have unspecified other
impact via a long line in a response. NOTE: This issue exists because of a
CVE-2005-0094 regression.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2011-3205?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| squid | 11.10 oneiric | Not affected |
| 11.04 natty | Not affected |
| 10.10 maverick | Not affected |
| 10.04 LTS lucid | Not affected |
| 8.04 LTS hardy | Not affected |
| squid3 | 11.10 oneiric | Fixed 3.1.14-1ubuntu0.1 |
| 11.04 natty | Fixed 3.1.11-1ubuntu0.1 |
| 10.10 maverick | Fixed 3.1.6-1.1ubuntu1.2 |
| 10.04 LTS lucid | Fixed 3.0.STABLE19-1ubuntu0.2 |
| 8.04 LTS hardy | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2011-3205?format=md#patch-details)

## Notes

---

### [sbeattie](https://launchpad.net/~sbeattie)

this issue only affects squid3; not squid2, due to read sizes
being increased. Referenced patch for v2 is a bugfix patch
only.

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| squid | * Other:   <http://www.squid-cache.org/Versions/v2/2.HEAD/changesets/12710.patch> |
| squid3 | * Other:   <http://www.squid-cache.org/Versions/v3/3.0/changesets/squid-3.0-9193.patch> * Other:   <http://www.squid-cache.org/Versions/v3/3.1/changesets/squid-3.1-10363.patch> * Other:   <http://www.squid-cache.org/Versions/v3/3.2/changesets/squid-3.2-11294.patch> * Vendor:   <http://www.debian.org/security/2011/dsa-2304> |

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3205)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2011-3205)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2011-3205)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2011-3205)

### Other references

* <https://bugzilla.redhat.com/show_bug.cgi?id=734583>
* <https://www.cve.org/CVERecord?id=CVE-2011-3205>
