CVE-2013-1839: Input Validation
Published Sep 30, 2013
·Updated
The strHdrAcptLangGetItem function in errorpage.cc in Squid 3.2.x before 3.2.9 and 3.3.x before 3.3.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a "," character in an Accept-Language header.
Affected Software
32 affected components
Squid-Cache Squid=3.2.0.1
Squid-Cache Squid=3.2.0.2
Squid-Cache Squid=3.2.0.3
Squid-Cache Squid=3.2.0.4
Squid-Cache Squid=3.2.0.5
Squid-Cache Squid=3.2.0.6
Squid-Cache Squid=3.2.0.7
Squid-Cache Squid=3.2.0.8
Squid-Cache Squid=3.2.0.9
Squid-Cache Squid=3.2.0.10
Squid-Cache Squid=3.2.0.11
Squid-Cache Squid=3.2.0.12
Squid-Cache Squid=3.2.0.13
Squid-Cache Squid=3.2.0.14
Squid-Cache Squid=3.2.0.15
Squid-Cache Squid=3.2.0.16
Squid-Cache Squid=3.2.0.17
Squid-Cache Squid=3.2.0.18
Squid-Cache Squid=3.2.0.19
Squid-Cache Squid=3.2.1
Squid-Cache Squid=3.2.2
Squid-Cache Squid=3.2.3
Squid-Cache Squid=3.2.4
Squid-Cache Squid=3.2.5
Squid-Cache Squid=3.2.6
Squid-Cache Squid=3.2.7
Squid-Cache Squid=3.2.8
Squid-Cache Squid=3.3.0
Squid-Cache Squid=3.3.0.2
Squid-Cache Squid=3.3.0.3
Squid-Cache Squid=3.3.1
Squid-Cache Squid=3.3.2
Event History
Sep 30, 2013
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-1839?
CVE-2013-1839 has a high severity rating as it leads to denial of service through CPU exhaustion.
2
How do I fix CVE-2013-1839?
To fix CVE-2013-1839, upgrade your Squid instance to version 3.2.9 or 3.3.3 or later.
3
What versions of Squid are affected by CVE-2013-1839?
CVE-2013-1839 affects Squid versions 3.2.x prior to 3.2.9 and 3.3.x prior to 3.3.3.
4
What type of attack is associated with CVE-2013-1839?
CVE-2013-1839 allows attackers to exploit a vulnerability in the Accept-Language header, causing an infinite loop.
5
Can CVE-2013-1839 be exploited remotely?
Yes, CVE-2013-1839 can be exploited remotely by sending a specially crafted Accept-Language header.