CVE-2014-6270: Buffer Overflow

Published Sep 10, 2014
·
Updated

Last updated 24 July 2024

Other sources

Off-by-one error in the snmpHandleUdp function in snmpcore.cc in Squid 2.x and 3.x, when an SNMP port is configured, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted UDP SNMP request, which triggers a heap-based buffer overflow.

Launchpad

Sebastian Krahmer discovered an off-by-one error, leading to a heap-based buffer overflow flaw, in the way Squid handled UDP SNMP requests. An unauthenticated, remote attacker could possibly use this flaw to crash Squid or, potentially, execute arbitrary code.

As noted in Sebastian's original report, an SNMP port must be configured. The default configuration of Squid for Red Hat Enterprise Linux 6 and 7 does not include an snmpport declaration (http://wiki.squid-cache.org/Features/Snmp).

Patch:

http://bugzillafiles.novell.org/attachment.cgi?id=605545

References:

https://bugzilla.novell.com/showbug.cgi?id=895773 http://seclists.org/oss-sec/2014/q3/542

Red Hat

Affected Software

182 affected componentsFixes available
Squid-Cache Squid=2.4.stable1
Squid-Cache Squid=2.4.stable2
Squid-Cache Squid=2.4.stable3
Squid-Cache Squid=2.4.stable4
Squid-Cache Squid=2.4.stable5
Squid-Cache Squid=2.4.stable6
Squid-Cache Squid=2.4.stable7
Squid-Cache Squid=2.5.stable1
Squid-Cache Squid=2.5.stable2
Squid-Cache Squid=2.5.stable3
Squid-Cache Squid=2.5.stable4
Squid-Cache Squid=2.5.stable5
Squid-Cache Squid=2.5.stable6
Squid-Cache Squid=2.5.stable7
Squid-Cache Squid=2.5.stable8
Squid-Cache Squid=2.5.stable9
Squid-Cache Squid=2.5.stable10
Squid-Cache Squid=2.5.stable11
Squid-Cache Squid=2.5.stable12
Squid-Cache Squid=2.5.stable13
Squid-Cache Squid=2.5.stable14
Squid-Cache Squid=2.6.stable1
Squid-Cache Squid=2.6.stable2
Squid-Cache Squid=2.6.stable3
Squid-Cache Squid=2.6.stable4
Squid-Cache Squid=2.6.stable5
Squid-Cache Squid=2.6.stable6
Squid-Cache Squid=2.6.stable7
Squid-Cache Squid=2.6.stable8
Squid-Cache Squid=2.6.stable9
Squid-Cache Squid=2.6.stable10
Squid-Cache Squid=2.6.stable11
Squid-Cache Squid=2.6.stable12
Squid-Cache Squid=2.6.stable13
Squid-Cache Squid=2.6.stable14
Squid-Cache Squid=2.6.stable15
Squid-Cache Squid=2.6.stable16
Squid-Cache Squid=2.6.stable17
Squid-Cache Squid=2.6.stable18
Squid-Cache Squid=2.6.stable19
Squid-Cache Squid=2.6.stable20
Squid-Cache Squid=2.6.stable21
Squid-Cache Squid=2.6.stable22
Squid-Cache Squid=2.6.stable23
Squid-Cache Squid=2.7.stable1
Squid-Cache Squid=2.7.stable2
Squid-Cache Squid=2.7.stable3
Squid-Cache Squid=2.7.stable4
Squid-Cache Squid=2.7.stable5
Squid-Cache Squid=2.7.stable6
Squid-Cache Squid=2.7.stable7
Squid-Cache Squid=2.7.stable8
Squid-Cache Squid=2.7.stable9
Squid-Cache Squid=3.0
Squid-Cache Squid=3.0
Squid-Cache Squid=3.0
Squid-Cache Squid=3.0
Squid-Cache Squid=3.0
Squid-Cache Squid=3.0
Squid-Cache Squid=3.0
Squid-Cache Squid=3.0
Squid-Cache Squid=3.0-rc4
Squid-Cache Squid=3.0.stable1
Squid-Cache Squid=3.0.stable2
Squid-Cache Squid=3.0.stable3
Squid-Cache Squid=3.0.stable4
Squid-Cache Squid=3.0.stable5
Squid-Cache Squid=3.0.stable6
Squid-Cache Squid=3.0.stable7
Squid-Cache Squid=3.0.stable8
Squid-Cache Squid=3.0.stable9
Squid-Cache Squid=3.0.stable10
Squid-Cache Squid=3.0.stable11
Squid-Cache Squid=3.0.stable11-rc1
Squid-Cache Squid=3.0.stable12
Squid-Cache Squid=3.0.stable13
Squid-Cache Squid=3.0.stable14
Squid-Cache Squid=3.0.stable15
Squid-Cache Squid=3.0.stable16
Squid-Cache Squid=3.0.stable16-rc1
Squid-Cache Squid=3.0.stable17
Squid-Cache Squid=3.0.stable18
Squid-Cache Squid=3.0.stable19
Squid-Cache Squid=3.0.stable20
Squid-Cache Squid=3.0.stable21
Squid-Cache Squid=3.0.stable22
Squid-Cache Squid=3.0.stable23
Squid-Cache Squid=3.0.stable24
Squid-Cache Squid=3.0.stable25
Squid-Cache Squid=3.1
Squid-Cache Squid=3.1.0.1
Squid-Cache Squid=3.1.0.2
Squid-Cache Squid=3.1.0.3
Squid-Cache Squid=3.1.0.4
Squid-Cache Squid=3.1.0.5
Squid-Cache Squid=3.1.0.6
Squid-Cache Squid=3.1.0.7
Squid-Cache Squid=3.1.0.8
Squid-Cache Squid=3.1.0.9
Squid-Cache Squid=3.1.0.10
Squid-Cache Squid=3.1.0.11
Squid-Cache Squid=3.1.0.12
Squid-Cache Squid=3.1.0.13
Squid-Cache Squid=3.1.0.14
Squid-Cache Squid=3.1.0.15
Squid-Cache Squid=3.1.0.16
Squid-Cache Squid=3.1.0.17
Squid-Cache Squid=3.1.0.18
Squid-Cache Squid=3.1.1
Squid-Cache Squid=3.1.2
Squid-Cache Squid=3.1.3
Squid-Cache Squid=3.1.4
Squid-Cache Squid=3.1.5
Squid-Cache Squid=3.1.5.1
Squid-Cache Squid=3.1.6
Squid-Cache Squid=3.1.7
Squid-Cache Squid=3.1.8
Squid-Cache Squid=3.1.9
Squid-Cache Squid=3.1.10
Squid-Cache Squid=3.1.11
Squid-Cache Squid=3.1.12
Squid-Cache Squid=3.1.13
Squid-Cache Squid=3.1.14
Squid-Cache Squid=3.1.15
Squid-Cache Squid=3.2.0.1
Squid-Cache Squid=3.2.0.2
Squid-Cache Squid=3.2.0.3
Squid-Cache Squid=3.2.0.4
Squid-Cache Squid=3.2.0.5
Squid-Cache Squid=3.2.0.6
Squid-Cache Squid=3.2.0.7
Squid-Cache Squid=3.2.0.8
Squid-Cache Squid=3.2.0.9
Squid-Cache Squid=3.2.0.10
Squid-Cache Squid=3.2.0.11
Squid-Cache Squid=3.2.0.12
Squid-Cache Squid=3.2.0.13
Squid-Cache Squid=3.2.0.14
Squid-Cache Squid=3.2.0.15
Squid-Cache Squid=3.2.0.16
Squid-Cache Squid=3.2.0.17
Squid-Cache Squid=3.2.0.18
Squid-Cache Squid=3.2.0.19
Squid-Cache Squid=3.2.1
Squid-Cache Squid=3.2.2
Squid-Cache Squid=3.2.3
Squid-Cache Squid=3.2.4
Squid-Cache Squid=3.2.5
Squid-Cache Squid=3.2.6
Squid-Cache Squid=3.2.7
Squid-Cache Squid=3.2.8
Squid-Cache Squid=3.2.9
Squid-Cache Squid=3.2.10
Squid-Cache Squid=3.2.11
Squid-Cache Squid=3.2.12
Squid-Cache Squid=3.3.0
Squid-Cache Squid=3.3.0.2
Squid-Cache Squid=3.3.0.3
Squid-Cache Squid=3.3.1
Squid-Cache Squid=3.3.2
Squid-Cache Squid=3.3.3
Squid-Cache Squid=3.3.4
Squid-Cache Squid=3.3.5
Squid-Cache Squid=3.3.6
Squid-Cache Squid=3.3.7
Squid-Cache Squid=3.3.8
Squid-Cache Squid=3.3.9
Squid-Cache Squid=3.3.10
Squid-Cache Squid=3.3.11
Squid-Cache Squid=3.3.12
Squid-Cache Squid=3.4.0.1
Squid-Cache Squid=3.4.0.2
Squid-Cache Squid=3.4.0.3
Squid-Cache Squid=3.4.1
Squid-Cache Squid=3.4.2
Squid-Cache Squid=3.4.3
Squid-Cache Squid=3.4.4
Squid-Cache Squid=3.4.5
Squid-Cache Squid=3.4.6
Squid-Cache Squid=3.4.7
Oracle Solaris=11.2
debian/squid
4.13-10+deb11u34.13-10+deb11u45.7-2+deb12u26.13-1

Remediation

Event History

Sep 10, 2014
Data Sourced
via Red Hat·05:48 AM
DescriptionSeverityAffected Software
Sep 12, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:12 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:09 AM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2014-6270?

CVE-2014-6270 has been classified as a medium risk vulnerability due to its potential to cause denial of service or arbitrary code execution.

2

How do I fix CVE-2014-6270?

To mitigate CVE-2014-6270, it is recommended to upgrade to a patched version of Squid, specifically versions 4.13-10+deb11u3, 5.7-2+deb12u2, or 6.12-1.

3

What types of systems are affected by CVE-2014-6270?

CVE-2014-6270 affects multiple versions of the Squid Web Proxy Cache, particularly versions from 2.x to 3.x.

4

What exploitation vector does CVE-2014-6270 utilize?

CVE-2014-6270 can be exploited by sending a crafted UDP SNMP request to the configured SNMP port of affected Squid instances.

5

What are the potential impacts of CVE-2014-6270?

The impacts of CVE-2014-6270 include a crash of the Squid service and possible arbitrary code execution.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203