MGASA-2014-0396
Dashboard / Vulnerabilities / MGASA-2014-0396
MGASA-2014-0396
Summary: Updated squid packages fix security vulnerabilities
Details: Updated squid packages fix security vulnerabilities: Due to incorrect buffer management Squid can be caused by an attacker to write outside its allocated SNMP buffer (CVE-2014-6270). Due to incorrect bounds checking Squid pinger binary is vulnerable to denial of service or information leak attack when processing larger than normal ICMP or ICMPv6 packets (CVE-2014-7141). Due to incorrect input validation Squid pinger binary is vulnerable to denial of service or information leak attacks when processing ICMP or ICMPv6 packets (CVE-2014-7142).
References: https://advisories.mageia.org/MGASA-2014-0396.html, https://bugs.mageia.org/show_bug.cgi?id=14150, http://www.squid-cache.org/Advisories/SQUID-2014_3.txt, http://www.squid-cache.org/Advisories/SQUID-2014_4.txt
Affected packages
Package
Name: squid
Purl: pkg:rpm/mageia/squid?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
