CVE-2014-6270: Oracle Solaris
Medium severity, CVSS 6.8. EPSS: 23.3% chance of exploitation in the next 30 days.
Off-by-one error in the snmpHandleUdp function in snmp_core.cc in Squid 2.x and 3.x, when an SNMP port is configured, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted UDP SNMP request, which triggers a heap-based buffer overflow.
Affected products
- Oracle Solaris: version 11.2 only
- Squid-Cache Squid: version 2.4.stable1 only; version 2.4.stable2 only; version 2.4.stable3 only; version 2.4.stable4 only; version 2.4.stable5 only; version 2.4.stable6 only; …
Published 2014-09-12. Last modified 2026-06-17.