Squid HTTP Header Port Number Handling Denial of Service Vulnerability


Description   A vulnerability has been reported in Squid, which can be exploited by malicious people to cause a DoS (Denial of Service).
The vulnerability is caused due to an error when handling port number values within the "Host" header of HTTP requests and can be exploited to render the service unusable.
The vulnerability is reported in versions 3.2 through 3.2.12 and versions 3.3 through 3.3.7.
     
Vulnerable Products   Vulnerable Software:
Squid 3.x
     
Solution   Update to version 3.2.13 or 3.3.8 or apply patch.
     
CVE   CVE-2013-4123
     
References   http://www.squid-cache.org/Advisories/SQUID-2013_3.txt
     
Vulnerability Manager Detection   No
     
IPS Protection  
ASQ Engine alarm Available Since
Possible buffer overflow in HTTP request/reply
3.2.0
     


 
 
 
 
 Risk level 
Moderate 

 Vulnerability First Public Report Date 
2013-07-15 

 Target Type 
Server 

 Possible exploit 
Remote