Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3609

Опубликовано: 28 авг. 2014
Источник: redhat
CVSS2: 5

Описание

HttpHdrRange.cc in Squid 3.x before 3.3.12 and 3.4.x before 3.4.6 allows remote attackers to cause a denial of service (crash) via a request with crafted "Range headers with unidentifiable byte-range values."

A flaw was found in the way Squid handled malformed HTTP Range headers. A remote attacker able to send HTTP requests to the Squid proxy could use this flaw to crash Squid.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4squidWill not fix
Red Hat Enterprise Linux 5squidFixedRHSA-2014:114803.09.2014
Red Hat Enterprise Linux 6squidFixedRHSA-2014:114803.09.2014
Red Hat Enterprise Linux 7squidFixedRHSA-2014:114703.09.2014

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-228->CWE-617
https://bugzilla.redhat.com/show_bug.cgi?id=1134209squid: assertion failure in Range header processing (SQUID-2014:2)

5 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 11 лет назад

HttpHdrRange.cc in Squid 3.x before 3.3.12 and 3.4.x before 3.4.6 allows remote attackers to cause a denial of service (crash) via a request with crafted "Range headers with unidentifiable byte-range values."

nvd
почти 11 лет назад

HttpHdrRange.cc in Squid 3.x before 3.3.12 and 3.4.x before 3.4.6 allows remote attackers to cause a denial of service (crash) via a request with crafted "Range headers with unidentifiable byte-range values."

debian
почти 11 лет назад

HttpHdrRange.cc in Squid 3.x before 3.3.12 and 3.4.x before 3.4.6 allo ...

github
около 3 лет назад

HttpHdrRange.cc in Squid 3.x before 3.3.12 and 3.4.x before 3.4.6 allows remote attackers to cause a denial of service (crash) via a request with crafted "Range headers with unidentifiable byte-range values."

oracle-oval
почти 11 лет назад

ELSA-2014-1147: squid security update (IMPORTANT)

5 Medium

CVSS2