Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-7141

Опубликовано: 09 сент. 2014
Источник: redhat
CVSS2: 1.8
EPSS Высокий

Описание

The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and crash) via a crafted type in an (1) ICMP or (2) ICMP6 packet.

Отчет

This issue did not affect the versions of squid as shipped with Red Hat Enterprise Linux 5, 6, and 7 as they do not provide the vulnerable program "pinger".

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4squidNot affected
Red Hat Enterprise Linux 5squidNot affected
Red Hat Enterprise Linux 6squidNot affected
Red Hat Enterprise Linux 7squidNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-129
https://bugzilla.redhat.com/show_bug.cgi?id=1139715squid: pinger OOB array index flaw in handling of ICMP replies (SQUID-2014:4)

EPSS

Процентиль: 99%
0.77333
Высокий

1.8 Low

CVSS2

Связанные уязвимости

ubuntu
около 11 лет назад

The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and crash) via a crafted type in an (1) ICMP or (2) ICMP6 packet.

nvd
около 11 лет назад

The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and crash) via a crafted type in an (1) ICMP or (2) ICMP6 packet.

debian
около 11 лет назад

The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain ...

github
больше 3 лет назад

The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and crash) via a crafted type in an (1) ICMP or (2) ICMP6 packet.

suse-cvrf
больше 9 лет назад

Security update for squid3

EPSS

Процентиль: 99%
0.77333
Высокий

1.8 Low

CVSS2