CVE-2016-3947

Publication date 7 April 2016

Last updated 24 July 2024


Ubuntu priority

Cvss 3 Severity Score

8.2 · High

Score breakdown

Heap-based buffer overflow in the Icmp6::Recv function in icmp/Icmp6.cc in the pinger utility in Squid before 3.5.16 and 4.x before 4.0.8 allows remote servers to cause a denial of service (performance degradation or transition failures) or write sensitive information to log files via an ICMPv6 packet.

Status

Package Ubuntu Release Status
squid3 16.04 LTS xenial
Fixed 3.5.12-1ubuntu7.2
15.10 wily
Fixed 3.3.8-1ubuntu16.3
14.04 LTS trusty
Fixed 3.3.8-1ubuntu6.8
12.04 LTS precise
Fixed 3.1.19-1ubuntu3.12.04.7

Severity score breakdown

Parameter Value
Base score 8.2 · High
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Scope Unchanged
Confidentiality None
Integrity impact Low
Availability impact High
Vector CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

References

Related Ubuntu Security Notices (USN)

Other references