CVE-2016-3947: Buffer Overflow
Heap-based buffer overflow in the Icmp6::Recv function in icmp/Icmp6.cc in the pinger utility in Squid before 3.5.16 and 4.x before 4.0.8 allows remote servers to cause a denial of service (performance degradation or transition failures) or write sensitive information to log files via an ICMPv6 packet.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3947?
CVE-2016-3947 is rated as a high severity vulnerability that can lead to denial of service and potential information leakage.
How do I fix CVE-2016-3947?
To fix CVE-2016-3947, upgrade to Squid version 3.5.16 or later, or 4.0.8 or later.
What versions of Squid are affected by CVE-2016-3947?
CVE-2016-3947 affects Squid versions prior to 3.5.16 and 4.x prior to 4.0.8.
Can CVE-2016-3947 be exploited remotely?
Yes, CVE-2016-3947 can be exploited remotely through crafted ICMPv6 packets.
What impact does CVE-2016-3947 have on system performance?
Exploitation of CVE-2016-3947 can cause performance degradation and transition failures in affected systems.