5
CVSSv2

CVE-2014-3609

Published: 11/09/2014 Updated: 07/01/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

HttpHdrRange.cc in Squid 3.x prior to 3.3.12 and 3.4.x prior to 3.4.6 allows remote malicious users to cause a denial of service (crash) via a request with crafted "Range headers with unidentifiable byte-range values."

Vulnerable Product Search on Vulmon Subscribe to Product

squid-cache squid 3.1

squid-cache squid 3.1.0.15

squid-cache squid 3.1.0.16

squid-cache squid 3.1.0.6

squid-cache squid 3.1.0.7

squid-cache squid 3.1.0.8

squid-cache squid 3.1.14

squid-cache squid 3.1.15

squid-cache squid 3.1.7

squid-cache squid 3.1.8

squid-cache squid 3.2.0.15

squid-cache squid 3.2.0.16

squid-cache squid 3.2.0.6

squid-cache squid 3.2.0.7

squid-cache squid 3.2.2

squid-cache squid 3.2.3

squid-cache squid 3.3.0

squid-cache squid 3.3.0.2

squid-cache squid 3.3.6

squid-cache squid 3.3.7

squid-cache squid 3.4.0.3

squid-cache squid 3.4.1

squid-cache squid 3.1.0.11

squid-cache squid 3.1.0.12

squid-cache squid 3.1.0.2

squid-cache squid 3.1.0.3

squid-cache squid 3.1.10

squid-cache squid 3.1.11

squid-cache squid 3.1.4

squid-cache squid 3.1.5

squid-cache squid 3.2.0.10

squid-cache squid 3.2.0.11

squid-cache squid 3.2.0.2

squid-cache squid 3.2.0.3

squid-cache squid 3.2.1

squid-cache squid 3.2.10

squid-cache squid 3.2.6

squid-cache squid 3.2.7

squid-cache squid 3.3.2

squid-cache squid 3.3.3

squid-cache squid 3.3.10

squid-cache squid 3.3.11

squid-cache squid 3.4.4

squid-cache squid 3.4.5

squid-cache squid 3.1.0.1

squid-cache squid 3.1.0.10

squid-cache squid 3.1.0.17

squid-cache squid 3.1.0.18

squid-cache squid 3.1.0.9

squid-cache squid 3.1.1

squid-cache squid 3.1.2

squid-cache squid 3.1.3

squid-cache squid 3.1.9

squid-cache squid 3.2.0.1

squid-cache squid 3.2.0.18

squid-cache squid 3.2.0.19

squid-cache squid 3.2.0.8

squid-cache squid 3.2.0.9

squid-cache squid 3.2.4

squid-cache squid 3.2.5

squid-cache squid 3.3.0.3

squid-cache squid 3.3.1

squid-cache squid 3.3.8

squid-cache squid 3.3.9

squid-cache squid 3.4.2

squid-cache squid 3.4.3

squid-cache squid 3.1.0.13

squid-cache squid 3.1.0.14

squid-cache squid 3.1.0.4

squid-cache squid 3.1.0.5

squid-cache squid 3.1.12

squid-cache squid 3.1.13

squid-cache squid 3.1.5.1

squid-cache squid 3.1.6

squid-cache squid 3.2.0.12

squid-cache squid 3.2.0.13

squid-cache squid 3.2.0.14

squid-cache squid 3.2.0.4

squid-cache squid 3.2.0.5

squid-cache squid 3.2.11

squid-cache squid 3.2.12

squid-cache squid 3.2.0.17

squid-cache squid 3.2.8

squid-cache squid 3.2.9

squid-cache squid 3.3.4

squid-cache squid 3.3.5

squid-cache squid 3.4.0.1

squid-cache squid 3.4.0.2

Vendor Advisories

Squid could be made to crash if it received specially crafted network traffic ...
Matthew Daley discovered that squid, a web proxy cache, does not properly perform input validation when parsing requests A remote attacker could use this flaw to mount a denial of service attack, by sending specially crafted Range requests For the stable distribution (wheezy), this problem has been fixed in version 27STABLE9-41+deb7u1 We reco ...
Debian Bug report logs - #759509 squid3: CVE-2014-3609: Denial of service in request processing Package: src:squid3; Maintainer for src:squid3 is Luigi Gangitano <luigi@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 27 Aug 2014 20:33:02 UTC Severity: important Tags: fixed-upstream, patc ...
Debian Bug report logs - #741312 squid3: CVE-2014-0128: Denial of Service in SSL-Bump Package: src:squid3; Maintainer for src:squid3 is Luigi Gangitano <luigi@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 11 Mar 2014 05:27:02 UTC Severity: normal Tags: fixed-upstream, security, upstrea ...
Debian Bug report logs - #760999 squid3: pinger remote DoS (CVE-2014-7141 CVE-214-7142) Package: src:squid3; Maintainer for src:squid3 is Luigi Gangitano <luigi@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 9 Sep 2014 18:57:07 UTC Severity: normal Tags: patch, security, upstream Foun ...
Debian Bug report logs - #761002 squid3: CVE-2014-6270: off by one in snmp subsystem Package: src:squid3; Maintainer for src:squid3 is Luigi Gangitano <luigi@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 9 Sep 2014 19:09:02 UTC Severity: important Tags: patch, security, upstream Foun ...
A flaw was found in the way Squid handled malformed HTTP Range headers A remote attacker able to send HTTP requests to the Squid proxy could use this flaw to crash Squid (CVE-2014-3609) A buffer overflow flaw was found in Squid's DNS lookup module A remote attacker able to send HTTP requests to the Squid proxy could use this flaw to crash Squid ...
A flaw was found in the way Squid handled malformed HTTP Range headers A remote attacker able to send HTTP requests to the Squid proxy could use this flaw to crash Squid (CVE-2014-3609) A buffer overflow flaw was found in Squid's DNS lookup module A remote attacker able to send HTTP requests to the Squid proxy could use this flaw to crash Squid ...
A flaw was found in the way Squid handled malformed HTTP Range headers A remote attacker able to send HTTP requests to the Squid proxy could use this flaw to crash Squid ...