6.4
CVSSv2

CVE-2014-7142

Published: 26/11/2014 Updated: 28/11/2016
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

The pinger in Squid 3.x prior to 3.4.8 allows remote malicious users to obtain sensitive information or cause a denial of service (crash) via a crafted (1) ICMP or (2) ICMP6 packet size.

Vulnerable Product Search on Vulmon Subscribe to Product

oracle solaris 11.2

canonical ubuntu linux 14.10

canonical ubuntu linux 14.04

squid-cache squid 3.4.5

squid-cache squid 3.4.4

squid-cache squid 3.1.1

squid-cache squid 3.1.10

squid-cache squid 3.1.17

squid-cache squid 3.1.18

squid-cache squid 3.1.19

squid-cache squid 3.1.5

squid-cache squid 3.1.5.1

squid-cache squid 3.2.0.11

squid-cache squid 3.2.0.12

squid-cache squid 3.2.0.2

squid-cache squid 3.2.0.3

squid-cache squid 3.2.1

squid-cache squid 3.2.10

squid-cache squid 3.2.6

squid-cache squid 3.2.7

squid-cache squid 3.3.10

squid-cache squid 3.3.11

squid-cache squid 3.3.7

squid-cache squid 3.3.8

squid-cache squid 3.4.7

squid-cache squid 3.4.6

squid-cache squid 3.4.0.2

squid-cache squid 3.4.0.1

squid-cache squid 3.1.15

squid-cache squid 3.1.16

squid-cache squid 3.1.3

squid-cache squid 3.1.4

squid-cache squid 3.2.0.1

squid-cache squid 3.2.0.10

squid-cache squid 3.2.0.17

squid-cache squid 3.2.0.18

squid-cache squid 3.2.0.19

squid-cache squid 3.2.0.8

squid-cache squid 3.2.0.9

squid-cache squid 3.2.4

squid-cache squid 3.2.5

squid-cache squid 3.3.0.3

squid-cache squid 3.3.1

squid-cache squid 3.3.5

squid-cache squid 3.3.6

squid-cache squid 3.4.1

squid-cache squid 3.4.0.3

squid-cache squid 3.1.13

squid-cache squid 3.1.14

squid-cache squid 3.1.21

squid-cache squid 3.1.22

squid-cache squid 3.1.8

squid-cache squid 3.1.9

squid-cache squid 3.2.0.15

squid-cache squid 3.2.0.16

squid-cache squid 3.2.0.6

squid-cache squid 3.2.0.7

squid-cache squid 3.2.2

squid-cache squid 3.2.3

squid-cache squid 3.3.0

squid-cache squid 3.3.0.1

squid-cache squid 3.3.0.2

squid-cache squid 3.3.3

squid-cache squid 3.3.4

squid-cache squid 3.4.3

squid-cache squid 3.4.2

squid-cache squid 3.1.11

squid-cache squid 3.1.12

squid-cache squid 3.1.2

squid-cache squid 3.1.20

squid-cache squid 3.1.6

squid-cache squid 3.1.7

squid-cache squid 3.2.0.13

squid-cache squid 3.2.0.14

squid-cache squid 3.2.0.4

squid-cache squid 3.2.0.5

squid-cache squid 3.2.11

squid-cache squid 3.2.12

squid-cache squid 3.2.8

squid-cache squid 3.2.9

squid-cache squid 3.3.12

squid-cache squid 3.3.2

squid-cache squid 3.3.9

Vendor Advisories

Squid could be made to crash if it received specially crafted network traffic ...
The pinger in Squid 3x before 348 allows remote attackers to obtain sensitive information or cause a denial of service (crash) via a crafted (1) ICMP or (2) ICMP6 packet size ...