MEDIUM
squid: off-by-one error in snmpHandleUdp() leading to a bss-based buffer overflow (SQUID-2014:3)
Published Sep 12, 2014
6.8
MEDIUMCVSS 2.0
EPSS 23.32%
Description
Off-by-one error in the snmpHandleUdp function in snmp_core.cc in Squid 2.x and 3.x, when an SNMP port is configured, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted UDP SNMP request, which triggers a heap-based buffer overflow.
Affected products
No data.
Configuration 1
OR
- 2.4.stable1
- 2.4.stable2
- 2.4.stable3
- 2.4.stable4
- 2.4.stable5
- 2.4.stable6
- 2.4.stable7
- 2.5.stable1
- 2.5.stable2
- 2.5.stable3
- 2.5.stable4
- 2.5.stable5
- 2.5.stable6
- 2.5.stable7
- 2.5.stable8
- 2.5.stable9
- 2.5.stable10
- 2.5.stable11
- 2.5.stable12
- 2.5.stable13
- 2.5.stable14
- 2.6.stable1
- 2.6.stable2
- 2.6.stable3
- 2.6.stable4
- 2.6.stable5
- 2.6.stable6
- 2.6.stable7
- 2.6.stable8
- 2.6.stable9
- 2.6.stable10
- 2.6.stable11
- 2.6.stable12
- 2.6.stable13
- 2.6.stable14
- 2.6.stable15
- 2.6.stable16
- 2.6.stable17
- 2.6.stable18
- 2.6.stable19
- 2.6.stable20
- 2.6.stable21
- 2.6.stable22
- 2.6.stable23
- 2.7.stable1
- 2.7.stable2
- 2.7.stable3
- 2.7.stable4
- 2.7.stable5
- 2.7.stable6
- 2.7.stable7
- 2.7.stable8
- 2.7.stable9
- 3.0
- 3.0
- 3.0
- 3.0
- 3.0
- 3.0
- 3.0
- 3.0
- 3.0
- 3.0.stable1
- 3.0.stable2
- 3.0.stable3
- 3.0.stable4
- 3.0.stable5
- 3.0.stable6
- 3.0.stable7
- 3.0.stable8
- 3.0.stable9
- 3.0.stable10
- 3.0.stable11
- 3.0.stable11
- 3.0.stable12
- 3.0.stable13
- 3.0.stable14
- 3.0.stable15
- 3.0.stable16
- 3.0.stable16
- 3.0.stable17
- 3.0.stable18
- 3.0.stable19
- 3.0.stable20
- 3.0.stable21
- 3.0.stable22
- 3.0.stable23
- 3.0.stable24
- 3.0.stable25
- 3.1
- 3.1.0.1
- 3.1.0.2
- 3.1.0.3
- 3.1.0.4
- 3.1.0.5
- 3.1.0.6
- 3.1.0.7
- 3.1.0.8
- 3.1.0.9
- 3.1.0.10
- 3.1.0.11
- 3.1.0.12
- 3.1.0.13
- 3.1.0.14
- 3.1.0.15
- 3.1.0.16
- 3.1.0.17
- 3.1.0.18
- 3.1.1
- 3.1.2
- 3.1.3
- 3.1.4
- 3.1.5
- 3.1.5.1
- 3.1.6
- 3.1.7
- 3.1.8
- 3.1.9
- 3.1.10
- 3.1.11
- 3.1.12
- 3.1.13
- 3.1.14
- 3.1.15
- 3.2.0.1
- 3.2.0.2
- 3.2.0.3
- 3.2.0.4
- 3.2.0.5
- 3.2.0.6
- 3.2.0.7
- 3.2.0.8
- 3.2.0.9
- 3.2.0.10
- 3.2.0.11
- 3.2.0.12
- 3.2.0.13
- 3.2.0.14
- 3.2.0.15
- 3.2.0.16
- 3.2.0.17
- 3.2.0.18
- 3.2.0.19
- 3.2.1
- 3.2.2
- 3.2.3
- 3.2.4
- 3.2.5
- 3.2.6
- 3.2.7
- 3.2.8
- 3.2.9
- 3.2.10
- 3.2.11
- 3.2.12
- 3.3.0
- 3.3.0.2
- 3.3.0.3
- 3.3.1
- 3.3.2
- 3.3.3
- 3.3.4
- 3.3.5
- 3.3.6
- 3.3.7
- 3.3.8
- 3.3.9
- 3.3.10
- 3.3.11
- 3.3.12
- 3.4.0.1
- 3.4.0.2
- 3.4.0.3
- 3.4.1
- 3.4.2
- 3.4.3
- 3.4.4
- 3.4.5
- 3.4.6
- 3.4.7
No data.
Red Hat Enterprise Linux 4
squid
Will not fix
Red Hat Enterprise Linux 5
squid
Will not fix
Red Hat Enterprise Linux 6
squid
Will not fix
Red Hat Enterprise Linux 7
squid
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | squid | Will not fix | n/a |
| Red Hat Enterprise Linux 5 | squid | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | squid | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | squid | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (15)
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00010.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00040.html vendor-advisoryx_refsource_SUSE
- http://seclists.org/oss-sec/2014/q3/542 mailing-listx_refsource_MLISTPatchThird Party AdvisoryVDB Entry
- http://seclists.org/oss-sec/2014/q3/550 mailing-listx_refsource_MLISTThird Party AdvisoryVDB Entry
- http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.html x_refsource_CONFIRMThird Party Advisory
- http://www.securityfocus.com/bid/69686 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.squid-cache.org/Advisories/SQUID-2014_3.txt
- http://www.ubuntu.com/usn/USN-2921-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2014-6270 Vendor Advisory
- https://bugzilla.novell.com/show_bug.cgi?id=895773 x_refsource_CONFIRMIssue TrackingThird Party AdvisoryVDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1139967 x_refsource_CONFIRMIssue TrackingThird Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95873 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2014-6270
- https://security.gentoo.org/glsa/201607-01 vendor-advisoryx_refsource_GENTOO
- https://www.cve.org/CVERecord?id=CVE-2014-6270
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 12, 2014
Updated Aug 6, 2024
Reserved Sep 9, 2014
Link CVE-2014-6270
CISA Vulnrichment
Updated n/a