PT-2014-1708 · Squid+3 · Squid+4

Stephane Chazelas

·

Publicado

2014-04-24

·

Atualizado

2017-09-08

·

CVE-2014-6270

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Squid versions 2.x through 3.x
Description The issue is related to an off-by-one error in the snmpHandleUdp function, which can be exploited by remote attackers. This error occurs when a specially crafted UDP SNMP request is sent, leading to a heap-based buffer overflow. As a result, attackers can cause a denial of service, leading to a crash, or possibly execute arbitrary code.
Recommendations For Squid versions 2.x through 3.x, consider disabling the SNMP port or restricting access to it until a patch is available. As a temporary workaround, avoid using the snmpHandleUdp function in the snmp core.cc file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-1531
ALT-PU-2015-1085
BDU:2015-00691
CVE-2014-6270
MGASA-2014-0396
SUSE-SU-2015:1983-1
SUSE-SU-2015_0028-1
SUSE-SU-2015_1983-1
SUSE-SU-2016:2089-1
USN-2921-1

Produtos afetados

Alt Linux
Squid
Squid Cache
Suse
Ubuntu