Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-3947

Опубликовано: 01 апр. 2016
Источник: redhat
CVSS2: 5.8
EPSS Высокий

Описание

Heap-based buffer overflow in the Icmp6::Recv function in icmp/Icmp6.cc in the pinger utility in Squid before 3.5.16 and 4.x before 4.0.8 allows remote servers to cause a denial of service (performance degradation or transition failures) or write sensitive information to log files via an ICMPv6 packet.

Отчет

This issue did not affect the versions of squid as shipped with Red Hat Enterprise Linux 5, 6 and 7 as they did not include support for ICMP pinging and the 'pinger' binary.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5squidNot affected
Red Hat Enterprise Linux 6squidNot affected
Red Hat Enterprise Linux 7squidNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1323590squid: buffer overrun in Squid proxy pinger

EPSS

Процентиль: 99%
0.7881
Высокий

5.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 8.2
ubuntu
почти 10 лет назад

Heap-based buffer overflow in the Icmp6::Recv function in icmp/Icmp6.cc in the pinger utility in Squid before 3.5.16 and 4.x before 4.0.8 allows remote servers to cause a denial of service (performance degradation or transition failures) or write sensitive information to log files via an ICMPv6 packet.

CVSS3: 8.2
nvd
почти 10 лет назад

Heap-based buffer overflow in the Icmp6::Recv function in icmp/Icmp6.cc in the pinger utility in Squid before 3.5.16 and 4.x before 4.0.8 allows remote servers to cause a denial of service (performance degradation or transition failures) or write sensitive information to log files via an ICMPv6 packet.

CVSS3: 8.2
debian
почти 10 лет назад

Heap-based buffer overflow in the Icmp6::Recv function in icmp/Icmp6.c ...

CVSS3: 8.2
github
больше 3 лет назад

Heap-based buffer overflow in the Icmp6::Recv function in icmp/Icmp6.cc in the pinger utility in Squid before 3.5.16 and 4.x before 4.0.8 allows remote servers to cause a denial of service (performance degradation or transition failures) or write sensitive information to log files via an ICMPv6 packet.

suse-cvrf
больше 9 лет назад

Security update for squid

EPSS

Процентиль: 99%
0.7881
Высокий

5.8 Medium

CVSS2