CVE-2014-7141Improper Validation of Array Index in Squid

Severity
6.4MEDIUMNVD
EPSS
77.3%
top 1.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 26
Latest updateMay 17

Description

The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and crash) via a crafted type in an (1) ICMP or (2) ICMP6 packet.

CVSS vector

AV:N/AC:L/C:P/I:N/A:PExploitability: 10.0 | Impact: 4.9

Affected Packages2 packages

Debiansquid/squid< 4.1-1+3
NVDsquid-cache/squid80 versions+79

Patches

🔴Vulnerability Details

3
GHSA
GHSA-2vjp-6qwj-v6m6: The pinger in Squid 32022-05-17
CVEList
CVE-2014-7141: The pinger in Squid 32014-11-26
OSV
CVE-2014-7141: The pinger in Squid 32014-11-26

📋Vendor Advisories

3
Ubuntu
Squid vulnerabilities2014-11-25
Red Hat
squid: pinger OOB array index flaw in handling of ICMP replies (SQUID-2014:4)2014-09-09
Debian
CVE-2014-7141: squid - The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive...2014

💬Community

1
Bugzilla
CVE-2014-7141 squid: pinger OOB array index flaw in handling of ICMP replies (SQUID-2014:4)2014-09-09
CVE-2014-7141 — Improper Validation of Array Index | cvebase