Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3609

Опубликовано: 28 авг. 2014
Источник: redhat
CVSS2: 5
EPSS Высокий

Описание

HttpHdrRange.cc in Squid 3.x before 3.3.12 and 3.4.x before 3.4.6 allows remote attackers to cause a denial of service (crash) via a request with crafted "Range headers with unidentifiable byte-range values."

A flaw was found in the way Squid handled malformed HTTP Range headers. A remote attacker able to send HTTP requests to the Squid proxy could use this flaw to crash Squid.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4squidWill not fix
Red Hat Enterprise Linux 5squidFixedRHSA-2014:114803.09.2014
Red Hat Enterprise Linux 6squidFixedRHSA-2014:114803.09.2014
Red Hat Enterprise Linux 7squidFixedRHSA-2014:114703.09.2014

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-228->CWE-617
https://bugzilla.redhat.com/show_bug.cgi?id=1134209squid: assertion failure in Range header processing (SQUID-2014:2)

EPSS

Процентиль: 99%
0.8285
Высокий

5 Medium

CVSS2

Связанные уязвимости

ubuntu
около 11 лет назад

HttpHdrRange.cc in Squid 3.x before 3.3.12 and 3.4.x before 3.4.6 allows remote attackers to cause a denial of service (crash) via a request with crafted "Range headers with unidentifiable byte-range values."

nvd
около 11 лет назад

HttpHdrRange.cc in Squid 3.x before 3.3.12 and 3.4.x before 3.4.6 allows remote attackers to cause a denial of service (crash) via a request with crafted "Range headers with unidentifiable byte-range values."

debian
около 11 лет назад

HttpHdrRange.cc in Squid 3.x before 3.3.12 and 3.4.x before 3.4.6 allo ...

github
больше 3 лет назад

HttpHdrRange.cc in Squid 3.x before 3.3.12 and 3.4.x before 3.4.6 allows remote attackers to cause a denial of service (crash) via a request with crafted "Range headers with unidentifiable byte-range values."

oracle-oval
около 11 лет назад

ELSA-2014-1147: squid security update (IMPORTANT)

EPSS

Процентиль: 99%
0.8285
Высокий

5 Medium

CVSS2