Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-7142

Опубликовано: 16 сент. 2014
Источник: redhat
CVSS2: 1.8

Описание

The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (crash) via a crafted (1) ICMP or (2) ICMP6 packet size.

Отчет

This issue did not affect the versions of squid as shipped with Red Hat Enterprise Linux 5, 6, and 7 as they do not provide the vulnerable program "pinger".

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4squidNot affected
Red Hat Enterprise Linux 5squidNot affected
Red Hat Enterprise Linux 6squidNot affected
Red Hat Enterprise Linux 7squidNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-129
https://bugzilla.redhat.com/show_bug.cgi?id=1148832squid: pinger incorrect input validation flaw in handling of ICMP replies (SQUID-2014:4)

1.8 Low

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (crash) via a crafted (1) ICMP or (2) ICMP6 packet size.

nvd
больше 11 лет назад

The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (crash) via a crafted (1) ICMP or (2) ICMP6 packet size.

debian
больше 11 лет назад

The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain ...

github
около 4 лет назад

The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (crash) via a crafted (1) ICMP or (2) ICMP6 packet size.

suse-cvrf
почти 10 лет назад

Security update for squid3

1.8 Low

CVSS2