CVE-2014-7142: Input Validation
The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (crash) via a crafted (1) ICMP or (2) ICMP6 packet size.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7142?
CVE-2014-7142 has a medium severity rating as it allows remote attackers to access sensitive information or potentially crash the system.
How do I fix CVE-2014-7142?
To fix CVE-2014-7142, upgrade to Squid version 3.4.8 or later, which includes the patch for this vulnerability.
What types of attacks are possible with CVE-2014-7142?
CVE-2014-7142 allows attackers to exploit crafted ICMP or ICMP6 packets to disrupt service or leak sensitive information.
Which versions of Squid are affected by CVE-2014-7142?
Squid versions before 3.4.8 are affected by CVE-2014-7142, specifically including versions from 3.1.1 to 3.4.7.
What kind of systems are vulnerable to CVE-2014-7142?
Systems running vulnerable versions of Squid, such as Oracle Solaris 11.2 and various Ubuntu Linux releases, are at risk from CVE-2014-7142.