CVE-2014-9749

Severity

40%

Complexity

80%

Confidentiality

48%

Squid 3.4.4 through 3.4.11 and 3.5.0.1 through 3.5.1, when Digest authentication is used, allow remote authenticated users to retain access by leveraging a stale nonce, aka "Nonce replay vulnerability."

Squid 3.4.4 through 3.4.11 and 3.5.0.1 through 3.5.1, when Digest authentication is used, allow remote authenticated users to retain access by leveraging a stale nonce, aka "Nonce replay vulnerability."

CVSS 2.0 Base Score 4. CVSS Attack Vector: network. CVSS Attack Complexity: low. CVSS Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).

Overview

First reported 9 years ago

2015-11-06 21:59:00

Last updated 6 years ago

2018-10-30 16:27:00

Affected Software

squid-cache.org Squid 3.4.4

3.4.4

squid-cache Squid 3.4.5

3.4.5

squid-cache Squid 3.4.6

3.4.6

squid-cache Squid 3.4.7

3.4.7

squid-cache.org Squid 3.4.8

3.4.8

squid-cache.org Squid 3.4.9

3.4.9

squid-cache.org Squid 3.4.10

3.4.10

squid-cache.org Squid 3.4.11

3.4.11

squid-cache.org Squid 3.4.12

3.4.12

squid-cache.org Squid 3.4.13

3.4.13

squid-cache.org Squid 3.5.0.1

3.5.0.1

squid-cache.org Squid 3.5.0.2

3.5.0.2

squid-cache.org Squid 3.5.0.3

3.5.0.3

squid-cache.org Squid 3.5.0.4

3.5.0.4

squid-cache.org Squid 3.5.1

3.5.1

OpenSUSE 13.1

13.1

OpenSUSE 13.2

13.2

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.