CVE-2013-4123: Input Validation
Published Sep 16, 2013
·Updated
clientsiderequest.cc in Squid 3.2.x before 3.2.13 and 3.3.x before 3.3.8 allows remote attackers to cause a denial of service via a crafted port number in a HTTP Host header.
Affected Software
42 affected components
Squid-Cache Squid=3.3.0
Squid-Cache Squid=3.3.0.2
Squid-Cache Squid=3.3.0.3
Squid-Cache Squid=3.3.1
Squid-Cache Squid=3.3.2
Squid-Cache Squid=3.3.3
Squid-Cache Squid=3.3.4
Squid-Cache Squid=3.3.5
Squid-Cache Squid=3.3.6
Squid-Cache Squid=3.3.7
openSUSE openSUSE=12.3
Squid-Cache Squid=3.2.0.1
Squid-Cache Squid=3.2.0.2
Squid-Cache Squid=3.2.0.3
Squid-Cache Squid=3.2.0.4
Squid-Cache Squid=3.2.0.5
Squid-Cache Squid=3.2.0.6
Squid-Cache Squid=3.2.0.7
Squid-Cache Squid=3.2.0.8
Squid-Cache Squid=3.2.0.9
Squid-Cache Squid=3.2.0.10
Squid-Cache Squid=3.2.0.11
Squid-Cache Squid=3.2.0.12
Squid-Cache Squid=3.2.0.13
Squid-Cache Squid=3.2.0.14
Squid-Cache Squid=3.2.0.15
Squid-Cache Squid=3.2.0.16
Squid-Cache Squid=3.2.0.17
Squid-Cache Squid=3.2.0.18
Squid-Cache Squid=3.2.0.19
Squid-Cache Squid=3.2.1
Squid-Cache Squid=3.2.2
Squid-Cache Squid=3.2.3
Squid-Cache Squid=3.2.4
Squid-Cache Squid=3.2.5
Squid-Cache Squid=3.2.6
Squid-Cache Squid=3.2.7
Squid-Cache Squid=3.2.8
Squid-Cache Squid=3.2.9
Squid-Cache Squid=3.2.10
Squid-Cache Squid=3.2.11
Squid-Cache Squid=3.2.12
Remediation
Event History
Sep 16, 2013
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the risk associated with CVE-2013-4123?
CVE-2013-4123 can lead to a denial of service, allowing remote attackers to crash the affected Squid server.
2
Which versions of Squid are affected by CVE-2013-4123?
CVE-2013-4123 affects Squid versions 3.2.0 to 3.2.12 and 3.3.0 to 3.3.7.
3
How can I resolve CVE-2013-4123?
To fix CVE-2013-4123, upgrade to Squid version 3.2.13 or later, or 3.3.8 or later.
4
What type of attack does CVE-2013-4123 facilitate?
CVE-2013-4123 facilitates a remote denial of service attack via a crafted HTTP Host header.
5
Are there any specific configurations to avoid with CVE-2013-4123?
Users should avoid using vulnerable versions of Squid or improperly configure the HTTP Host header in their requests.