USN-2921-1: Squid vulnerabilities
Sebastian Krahmer discovered that Squid incorrectly handled certain SNMP requests. If SNMP is enabled, a remote attacker could use this issue to cause Squid to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2014-6270) Alex Rousskov discovered that Squid incorrectly handled certain malformed responses. A remote attacker could possibly use this issue to cause Squid to crash, resulting in a denial of service. (CVE-2016-2571)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2014-6270.
What is the severity of CVE-2014-6270?
The severity of CVE-2014-6270 is high.
How does CVE-2014-6270 affect Squid?
CVE-2014-6270 affects Squid by allowing a remote attacker to cause a denial of service or possibly execute arbitrary code.
What is the recommended version of Squid3 to fix CVE-2014-6270?
The recommended version of Squid3 to fix CVE-2014-6270 is 3.3.8-1ubuntu16.2.
Where can I find more information about CVE-2014-6270?
You can find more information about CVE-2014-6270 at the following link: [CVE-2014-6270](https://ubuntu.com/security/CVE-2014-6270)