5
CVSSv2

CVE-2012-5643

Published: 20/12/2012 Updated: 13/02/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Multiple memory leaks in tools/cachemgr.cc in cachemgr.cgi in Squid 2.x and 3.x prior to 3.1.22, 3.2.x prior to 3.2.4, and 3.3.x prior to 3.3.0.2 allow remote malicious users to cause a denial of service (memory consumption) via (1) invalid Content-Length headers, (2) long POST requests, or (3) crafted authentication credentials.

Vulnerable Product Search on Vulmon Subscribe to Product

squid-cache squid 2.6

squid-cache squid 2.0

squid-cache squid 2.7

squid-cache squid 2.2

squid-cache squid 2.3

squid-cache squid 2.5

squid-cache squid 2.1

squid-cache squid 2.4

squid-cache squid 3.1.0.18

squid-cache squid 3.0.stable13

squid-cache squid 3.1.21

squid-cache squid 3.0

squid-cache squid 3.0.stable9

squid-cache squid 3.1.13

squid-cache squid 3.0.stable20

squid-cache squid 3.0.stable14

squid-cache squid 3.0.stable3

squid-cache squid 3.1.17

squid-cache squid 3.1.0.7

squid-cache squid 3.1.0.14

squid-cache squid 3.0.stable4

squid-cache squid 3.1.0.12

squid-cache squid 3.1.1

squid-cache squid 3.0.stable24

squid-cache squid 3.1.0.3

squid-cache squid 3.1.0.1

squid-cache squid 3.0.stable16

squid-cache squid 3.1.18

squid-cache squid 3.1.14

squid-cache squid 3.0.stable11

squid-cache squid 3.0.stable18

squid-cache squid 3.0.stable1

squid-cache squid 3.1.0.9

squid-cache squid 3.1.0.15

squid-cache squid 3.1.15

squid-cache squid 3.0.stable6

squid-cache squid 3.1.0.13

squid-cache squid 3.1.12

squid-cache squid 3.0.stable15

squid-cache squid 3.1.10

squid-cache squid 3.1.0.2

squid-cache squid 3.0.stable5

squid-cache squid 3.0.stable21

squid-cache squid 3.1.0.6

squid-cache squid 3.1.0.4

squid-cache squid 3.0.stable17

squid-cache squid 3.1

squid-cache squid 3.1.0.16

squid-cache squid 3.1.11

squid-cache squid 3.1.0.8

squid-cache squid 3.0.stable10

squid-cache squid 3.0.stable8

squid-cache squid 3.1.2

squid-cache squid 3.1.20

squid-cache squid 3.1.0.5

squid-cache squid 3.1.0.10

squid-cache squid 3.0.stable12

squid-cache squid 3.0.stable25

squid-cache squid 3.0.stable23

squid-cache squid 3.1.19

squid-cache squid 3.0.stable22

squid-cache squid 3.1.0.11

squid-cache squid 3.0.stable2

squid-cache squid 3.0.stable7

squid-cache squid 3.1.0.17

squid-cache squid 3.0.stable19

squid-cache squid 3.1.16

squid-cache squid 3.2.0.18

squid-cache squid 3.2.0.9

squid-cache squid 3.2.0.1

squid-cache squid 3.2.2

squid-cache squid 3.2.0.6

squid-cache squid 3.2.0.15

squid-cache squid 3.2.0.19

squid-cache squid 3.2.0.13

squid-cache squid 3.2.0.16

squid-cache squid 3.2.0.10

squid-cache squid 3.2.0.7

squid-cache squid 3.2.0.11

squid-cache squid 3.2.0.3

squid-cache squid 3.2.0.4

squid-cache squid 3.2.3

squid-cache squid 3.2.0.12

squid-cache squid 3.2.1

squid-cache squid 3.2.0.2

squid-cache squid 3.2.0.8

squid-cache squid 3.2.0.5

squid-cache squid 3.2.0.14

squid-cache squid 3.2.0.17

squid-cache squid 3.3.0.1

Vendor Advisories

Synopsis Moderate: squid security and bug fix update Type/Severity Security Advisory: Moderate Topic Updated squid packages that fix one security issue and several bugs are nowavailable for Red Hat Enterprise Linux 6The Red Hat Security Response Team has rated this update as having moderatesecurity impact ...
squid-cgi could consume excessive system resources, leading to a denial of service attack on it and other hosted services ...
Debian Bug report logs - #696187 CVE-2012-5643: cachemgrcgi denial of service Package: squid-cgi; Maintainer for squid-cgi is Luigi Gangitano <luigi@debianorg>; Source for squid-cgi is src:squid (PTS, buildd, popcon) Reported by: Henri Salo <henri@nervfi> Date: Mon, 17 Dec 2012 19:39:02 UTC Severity: grave Tags: ...
Debian Bug report logs - #521052 CVE-2009-0801: HTTP Host Header Incorrect Relay Behavior Vulnerability Package: squid3; Maintainer for squid3 is Luigi Gangitano <luigi@debianorg>; Source for squid3 is src:squid (PTS, buildd, popcon) Reported by: Raphael Geissert <atomo64@gmailcom> Date: Tue, 24 Mar 2009 15:15:01 U ...
Squid3, a fully featured Web proxy cache, is prone to a denial of service attack due to memory consumption caused by memory leaks in cachemgrcgi: CVE-2012-5643 squid's cachemgrcgi was vulnerable to excessive resource use A remote attacker could exploit this flaw to perform a denial of service attack on the server and other hosted se ...