6.8
CVSSv2

CVE-2014-6270

Published: 12/09/2014 Updated: 08/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Off-by-one error in the snmpHandleUdp function in snmp_core.cc in Squid 2.x and 3.x, when an SNMP port is configured, allows remote malicious users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted UDP SNMP request, which triggers a heap-based buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

squid-cache squid 2.7.stable2

squid-cache squid 2.7.stable3

squid-cache squid 2.7.stable1

squid-cache squid 2.7.stable8

squid-cache squid 2.7.stable9

squid-cache squid 2.6.stable8

squid-cache squid 2.6.stable9

squid-cache squid 2.6.stable16

squid-cache squid 2.6.stable17

squid-cache squid 2.5.stable1

squid-cache squid 2.5.stable2

squid-cache squid 2.5.stable10

squid-cache squid 2.5.stable11

squid-cache squid 2.4.stable4

squid-cache squid 2.4.stable5

squid-cache squid 3.0

squid-cache squid 3.0.stable12

squid-cache squid 3.0.stable13

squid-cache squid 3.0.stable19

squid-cache squid 3.0.stable2

squid-cache squid 3.0.stable3

squid-cache squid 3.0.stable4

squid-cache squid 3.0.stable5

squid-cache squid 3.1.0.10

squid-cache squid 3.1.0.11

squid-cache squid 3.1.0.18

squid-cache squid 3.1.0.2

squid-cache squid 3.1.0.9

squid-cache squid 3.1.1

squid-cache squid 3.1.10

squid-cache squid 3.1.3

squid-cache squid 3.1.4

squid-cache squid 3.2.0.1

squid-cache squid 3.2.0.10

squid-cache squid 3.2.0.18

squid-cache squid 3.2.0.19

squid-cache squid 3.2.0.8

squid-cache squid 3.2.0.9

squid-cache squid 3.2.4

squid-cache squid 3.2.5

squid-cache squid 3.3.1

squid-cache squid 3.3.10

squid-cache squid 3.3.6

squid-cache squid 3.3.7

squid-cache squid 3.4.2

squid-cache squid 3.4.3

squid-cache squid 2.7.stable6

squid-cache squid 2.7.stable7

squid-cache squid 2.6.stable5

squid-cache squid 2.6.stable6

squid-cache squid 2.6.stable7

squid-cache squid 2.6.stable14

squid-cache squid 2.6.stable15

squid-cache squid 2.6.stable22

squid-cache squid 2.6.stable23

squid-cache squid 2.5.stable8

squid-cache squid 2.5.stable9

squid-cache squid 2.4.stable2

squid-cache squid 2.4.stable3

squid-cache squid 3.0.stable11

squid-cache squid 3.0.stable17

squid-cache squid 3.0.stable18

squid-cache squid 3.0.stable24

squid-cache squid 3.0.stable25

squid-cache squid 3.1

squid-cache squid 3.1.0.1

squid-cache squid 3.1.0.16

squid-cache squid 3.1.0.17

squid-cache squid 3.1.0.7

squid-cache squid 3.1.0.8

squid-cache squid 3.1.15

squid-cache squid 3.1.2

squid-cache squid 3.1.8

squid-cache squid 3.1.9

squid-cache squid 3.2.0.15

squid-cache squid 3.2.0.16

squid-cache squid 3.2.0.17

squid-cache squid 3.2.0.6

squid-cache squid 3.2.0.7

squid-cache squid 3.2.2

squid-cache squid 3.2.3

squid-cache squid 3.3.0.2

squid-cache squid 3.3.0.3

squid-cache squid 3.3.4

squid-cache squid 3.3.5

squid-cache squid 3.4.0.3

squid-cache squid 3.4.1

squid-cache squid 2.7.stable4

squid-cache squid 2.7.stable5

squid-cache squid 2.6.stable3

squid-cache squid 2.6.stable4

squid-cache squid 2.6.stable12

squid-cache squid 2.6.stable13

squid-cache squid 2.6.stable20

squid-cache squid 2.6.stable21

squid-cache squid 2.5.stable5

squid-cache squid 2.5.stable6

squid-cache squid 2.5.stable7

squid-cache squid 2.5.stable14

squid-cache squid 2.4.stable1

squid-cache squid 3.0.stable1

squid-cache squid 3.0.stable10

squid-cache squid 3.0.stable16

squid-cache squid 3.0.stable22

squid-cache squid 3.0.stable23

squid-cache squid 3.0.stable8

squid-cache squid 3.0.stable9

squid-cache squid 3.1.0.14

squid-cache squid 3.1.0.15

squid-cache squid 3.1.0.5

squid-cache squid 3.1.0.6

squid-cache squid 3.1.13

squid-cache squid 3.1.14

squid-cache squid 3.1.6

squid-cache squid 3.1.7

squid-cache squid 3.2.0.13

squid-cache squid 3.2.0.14

squid-cache squid 3.2.0.4

squid-cache squid 3.2.0.5

squid-cache squid 3.2.11

squid-cache squid 3.2.12

squid-cache squid 3.2.8

squid-cache squid 3.2.9

squid-cache squid 3.3.0

squid-cache squid 3.3.2

squid-cache squid 3.3.3

squid-cache squid 3.4.0.1

squid-cache squid 3.4.0.2

squid-cache squid 3.4.7

squid-cache squid 2.6.stable1

squid-cache squid 2.6.stable2

squid-cache squid 2.6.stable10

squid-cache squid 2.6.stable11

squid-cache squid 2.6.stable18

squid-cache squid 2.6.stable19

squid-cache squid 2.5.stable3

squid-cache squid 2.5.stable4

squid-cache squid 2.5.stable12

squid-cache squid 2.5.stable13

squid-cache squid 2.4.stable6

squid-cache squid 2.4.stable7

squid-cache squid 3.0.stable14

squid-cache squid 3.0.stable15

squid-cache squid 3.0.stable20

squid-cache squid 3.0.stable21

squid-cache squid 3.0.stable6

squid-cache squid 3.0.stable7

squid-cache squid 3.1.0.12

squid-cache squid 3.1.0.13

squid-cache squid 3.1.0.3

squid-cache squid 3.1.0.4

squid-cache squid 3.1.11

squid-cache squid 3.1.12

squid-cache squid 3.1.5

squid-cache squid 3.1.5.1

squid-cache squid 3.2.0.11

squid-cache squid 3.2.0.12

squid-cache squid 3.2.0.2

squid-cache squid 3.2.0.3

squid-cache squid 3.2.1

squid-cache squid 3.2.10

squid-cache squid 3.2.6

squid-cache squid 3.2.7

squid-cache squid 3.3.11

squid-cache squid 3.3.12

squid-cache squid 3.3.8

squid-cache squid 3.3.9

squid-cache squid 3.4.4

squid-cache squid 3.4.5

squid-cache squid 3.4.6

oracle solaris 11.2

Vendor Advisories

Several security issues were fixed in Squid ...
Debian Bug report logs - #741312 squid3: CVE-2014-0128: Denial of Service in SSL-Bump Package: src:squid3; Maintainer for src:squid3 is Luigi Gangitano <luigi@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 11 Mar 2014 05:27:02 UTC Severity: normal Tags: fixed-upstream, security, upstrea ...
Debian Bug report logs - #760999 squid3: pinger remote DoS (CVE-2014-7141 CVE-214-7142) Package: src:squid3; Maintainer for src:squid3 is Luigi Gangitano <luigi@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 9 Sep 2014 18:57:07 UTC Severity: normal Tags: patch, security, upstream Foun ...
Debian Bug report logs - #761002 squid3: CVE-2014-6270: off by one in snmp subsystem Package: src:squid3; Maintainer for src:squid3 is Luigi Gangitano <luigi@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 9 Sep 2014 19:09:02 UTC Severity: important Tags: patch, security, upstream Foun ...
Off-by-one error in the snmpHandleUdp function in snmp_corecc in Squid 2x and 3x, when an SNMP port is configured, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted UDP SNMP request, which triggers a heap-based buffer overflow ...