Integer overflow in Varnish Cache - CVE-2017-12425
Published: September 4, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform denial of service attack.
The vulnerability exists due to integer overflow when processing HTTP requests. A remote attacker can send a specially crafted HTTP request, trigger integer overflow and restart the caching server.
Successful exploitation of this vulnerability may allow an attacker to perform denial if service (DoS) attack.
Affected software
Arch Linux
Fedora
varnish (Alpine package)
varnish
How to mitigate CVE-2017-12425
varnish (Alpine package) - update to 4.1.2-r2
varnish - addressed in versions 4.0.5-1.el7, 4.1.8-1.fc24, 5.0.0-4.fc25, 5.1.3-2.fc26