CVE-2014-6270: Oracle Solaris

Medium severity, CVSS 6.8. EPSS: 23.3% chance of exploitation in the next 30 days.

Off-by-one error in the snmpHandleUdp function in snmp_core.cc in Squid 2.x and 3.x, when an SNMP port is configured, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted UDP SNMP request, which triggers a heap-based buffer overflow.

Affected products

  • Oracle Solaris: version 11.2 only
  • Squid-Cache Squid: version 2.4.stable1 only; version 2.4.stable2 only; version 2.4.stable3 only; version 2.4.stable4 only; version 2.4.stable5 only; version 2.4.stable6 only; …

Published 2014-09-12. Last modified 2026-06-17.