Heap-based buffer overflow in the Icmp6::Recv function in icmp/Icmp6.cc in the pinger utility in Squid before 3.5.16 and 4.x before 4.0.8 allows remote servers to cause a denial of service (performance degradation or transition failures) or write sensitive information to log files via an ICMPv6 packet.
CVSS Details
- CVSS 3.1 Base Score: 8.2
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade squid | Aug 30, 2017 | Apr 7, 2016 |
| Debian | — | Upgrade squid | Jul 30, 2024 | Apr 7, 2016 |
| Freebsd | — | Upgrade squid | Dec 10, 2025 | Apr 2, 2016 |
| Gentoo Linux | — | Upgrade net-proxy/squid. | Oct 30, 2017 | Apr 7, 2016 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | Oct 19, 2018 | Apr 7, 2016 |
| Suse | — | Upgrade squidUpgrade squid3 | Aug 26, 2016 | Apr 7, 2016 |
| Ubuntu | — | Upgrade squid3Upgrade squid-cgi | Jun 9, 2016 | Apr 7, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub