CVE-2014-7141 — Improper Validation of Array Index in Squid
Severity
6.4MEDIUMNVD
EPSS
77.3%
top 1.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 26
Latest updateMay 17
Description
The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and crash) via a crafted type in an (1) ICMP or (2) ICMP6 packet.
CVSS vector
AV:N/AC:L/C:P/I:N/A:PExploitability: 10.0 | Impact: 4.9
Affected Packages2 packages
Patches
🔴Vulnerability Details
3📋Vendor Advisories
3💬Community
1Bugzilla▶
CVE-2014-7141 squid: pinger OOB array index flaw in handling of ICMP replies (SQUID-2014:4)↗2014-09-09