CVE-2014-6270
Last modified
CVE-2014-6270 is a vulnerability of currently unknown severity. Off-by-one error in the snmpHandleUdp function in snmp_core.cc in Squid 2.x and 3.x, when an SNMP port is configured, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted UDP SNMP request, which triggers a heap-based buffer overflow.. EPSS estimates a 23.32% chance of exploitation in the next 30 days.
Description
Off-by-one error in the snmpHandleUdp function in snmp_core.cc in Squid 2.x and 3.x, when an SNMP port is configured, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted UDP SNMP request, which triggers a heap-based buffer overflow.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Squid-Cache | Squid | 2.4.stable1 |
| Squid-Cache | Squid | 2.4.stable2 |
| Squid-Cache | Squid | 2.4.stable3 |
| Squid-Cache | Squid | 2.4.stable4 |
| Squid-Cache | Squid | 2.4.stable5 |
| Squid-Cache | Squid | 2.4.stable6 |
| Squid-Cache | Squid | 2.4.stable7 |
| Squid-Cache | Squid | 2.5.stable1 |
| Squid-Cache | Squid | 2.5.stable2 |
| Squid-Cache | Squid | 2.5.stable3 |
| Squid-Cache | Squid | 2.5.stable4 |
| Squid-Cache | Squid | 2.5.stable5 |
| Squid-Cache | Squid | 2.5.stable6 |
| Squid-Cache | Squid | 2.5.stable7 |
| Squid-Cache | Squid | 2.5.stable8 |
| Squid-Cache | Squid | 2.5.stable9 |
| Squid-Cache | Squid | 2.5.stable10 |
| Squid-Cache | Squid | 2.5.stable11 |
| Squid-Cache | Squid | 2.5.stable12 |
| Squid-Cache | Squid | 2.5.stable13 |
| Squid-Cache | Squid | 2.5.stable14 |
| Squid-Cache | Squid | 2.6.stable1 |
| Squid-Cache | Squid | 2.6.stable2 |
| Squid-Cache | Squid | 2.6.stable3 |
| Squid-Cache | Squid | 2.6.stable4 |
| Squid-Cache | Squid | 2.6.stable5 |
| Squid-Cache | Squid | 2.6.stable6 |
| Squid-Cache | Squid | 2.6.stable7 |
| Squid-Cache | Squid | 2.6.stable8 |
| Squid-Cache | Squid | 2.6.stable9 |
| Squid-Cache | Squid | 2.6.stable10 |
| Squid-Cache | Squid | 2.6.stable11 |
| Squid-Cache | Squid | 2.6.stable12 |
| Squid-Cache | Squid | 2.6.stable13 |
| Squid-Cache | Squid | 2.6.stable14 |
| Squid-Cache | Squid | 2.6.stable15 |
| Squid-Cache | Squid | 2.6.stable16 |
| Squid-Cache | Squid | 2.6.stable17 |
| Squid-Cache | Squid | 2.6.stable18 |
| Squid-Cache | Squid | 2.6.stable19 |
| Squid-Cache | Squid | 2.6.stable20 |
| Squid-Cache | Squid | 2.6.stable21 |
| Squid-Cache | Squid | 2.6.stable22 |
| Squid-Cache | Squid | 2.6.stable23 |
| Squid-Cache | Squid | 2.7.stable1 |
| Squid-Cache | Squid | 2.7.stable2 |
| Squid-Cache | Squid | 2.7.stable3 |
| Squid-Cache | Squid | 2.7.stable4 |
| Squid-Cache | Squid | 2.7.stable5 |
| Squid-Cache | Squid | 2.7.stable6 |
Showing 50 of 171 affected configurations. See NVD for the full list.
References
- http://seclists.org/oss-sec/2014/q3/542Patch, Third Party Advisory, VDB Entry
- http://seclists.org/oss-sec/2014/q3/550Third Party Advisory, VDB Entry
- http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.htmlThird Party Advisory
- http://www.securityfocus.com/bid/69686Third Party Advisory, VDB Entry
- https://bugzilla.novell.com/show_bug.cgi?id=895773Issue Tracking, Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1139967Issue Tracking, Third Party Advisory, VDB Entry
- http://seclists.org/oss-sec/2014/q3/542Patch, Third Party Advisory, VDB Entry
- http://seclists.org/oss-sec/2014/q3/550Third Party Advisory, VDB Entry
- http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.htmlThird Party Advisory
- http://www.securityfocus.com/bid/69686Third Party Advisory, VDB Entry
- https://bugzilla.novell.com/show_bug.cgi?id=895773Issue Tracking, Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1139967Issue Tracking, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-6270?
How severe is CVE-2014-6270?
How do I fix CVE-2014-6270?
Are you affected by CVE-2014-6270?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
