CVE-2014-7141: Medium severity squid web proxy cache vulnerability
Published Nov 26, 2014
·Updated
The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and crash) via a crafted type in an (1) ICMP or (2) ICMP6 packet.
Affected Software
80 affected components
Squid-Cache Squid=3.1.1
Squid-Cache Squid=3.1.2
Squid-Cache Squid=3.1.3
Squid-Cache Squid=3.1.4
Squid-Cache Squid=3.1.5
Squid-Cache Squid=3.1.5.1
Squid-Cache Squid=3.1.6
Squid-Cache Squid=3.1.7
Squid-Cache Squid=3.1.8
Squid-Cache Squid=3.1.9
Squid-Cache Squid=3.1.10
Squid-Cache Squid=3.1.11
Squid-Cache Squid=3.1.12
Squid-Cache Squid=3.1.13
Squid-Cache Squid=3.1.14
Squid-Cache Squid=3.1.15
Squid-Cache Squid=3.1.16
Squid-Cache Squid=3.1.17
Squid-Cache Squid=3.1.18
Squid-Cache Squid=3.1.19
Squid-Cache Squid=3.1.20
Squid-Cache Squid=3.1.21
Squid-Cache Squid=3.1.22
Squid-Cache Squid=3.2.0.1
Squid-Cache Squid=3.2.0.2
Squid-Cache Squid=3.2.0.3
Squid-Cache Squid=3.2.0.4
Squid-Cache Squid=3.2.0.5
Squid-Cache Squid=3.2.0.6
Squid-Cache Squid=3.2.0.7
Squid-Cache Squid=3.2.0.8
Squid-Cache Squid=3.2.0.9
Squid-Cache Squid=3.2.0.10
Squid-Cache Squid=3.2.0.11
Squid-Cache Squid=3.2.0.12
Squid-Cache Squid=3.2.0.13
Squid-Cache Squid=3.2.0.14
Squid-Cache Squid=3.2.0.15
Squid-Cache Squid=3.2.0.16
Squid-Cache Squid=3.2.0.17
Squid-Cache Squid=3.2.0.18
Squid-Cache Squid=3.2.0.19
Squid-Cache Squid=3.2.1
Squid-Cache Squid=3.2.2
Squid-Cache Squid=3.2.3
Squid-Cache Squid=3.2.4
Squid-Cache Squid=3.2.5
Squid-Cache Squid=3.2.6
Squid-Cache Squid=3.2.7
Squid-Cache Squid=3.2.8
Squid-Cache Squid=3.2.9
Squid-Cache Squid=3.2.10
Squid-Cache Squid=3.2.11
Squid-Cache Squid=3.2.12
Squid-Cache Squid=3.3.0
Squid-Cache Squid=3.3.0.1
Squid-Cache Squid=3.3.0.2
Squid-Cache Squid=3.3.0.3
Squid-Cache Squid=3.3.1
Squid-Cache Squid=3.3.2
Squid-Cache Squid=3.3.3
Squid-Cache Squid=3.3.4
Squid-Cache Squid=3.3.5
Squid-Cache Squid=3.3.6
Squid-Cache Squid=3.3.7
Squid-Cache Squid=3.3.8
Squid-Cache Squid=3.3.9
Squid-Cache Squid=3.3.10
Squid-Cache Squid=3.3.11
Squid-Cache Squid=3.3.12
Squid-Cache Squid=3.4.0.1
Squid-Cache Squid=3.4.0.2
Squid-Cache Squid=3.4.0.3
Squid-Cache Squid=3.4.1
Squid-Cache Squid=3.4.2
Squid-Cache Squid=3.4.3
Squid-Cache Squid=3.4.4
Squid-Cache Squid=3.4.5
Squid-Cache Squid=3.4.6
Squid-Cache Squid=3.4.7
Remediation
Patch Available
Event History
Nov 26, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-7141?
CVE-2014-7141 has a medium severity rating, allowing remote attackers to cause denial of service or disclose sensitive information.
2
How do I fix CVE-2014-7141?
To fix CVE-2014-7141, upgrade to Squid version 3.4.8 or later.
3
Which versions of Squid are affected by CVE-2014-7141?
CVE-2014-7141 affects Squid versions 3.x before 3.4.8.
4
What exposure does CVE-2014-7141 provide to attackers?
CVE-2014-7141 allows attackers to exploit crafted ICMP or ICMP6 packets, potentially leading to denial of service or data leakage.
5
Can CVE-2014-7141 crash my Squid server?
Yes, CVE-2014-7141 can lead to an out-of-bounds read and crash the Squid service.