#VU42563 Input validation error in Squid and Opensuse - CVE-2013-4123
Published: September 16, 2013 / Updated: August 11, 2020
Vulnerability identifier: #VU42563
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/U:Green
CVE-ID: CVE-2013-4123
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerable software:
Squid
Opensuse
Squid
Opensuse
Software vendor:
Squid-cache.org
SUSE
Squid-cache.org
SUSE
Description
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
client_side_request.cc in Squid 3.2.x before 3.2.13 and 3.3.x before 3.3.8 allows remote attackers to cause a denial of service via a crafted port number in a HTTP Host header.
Remediation
Install update from vendor's website.
External links
- http://lists.opensuse.org/opensuse-updates/2013-09/msg00024.html
- http://secunia.com/advisories/54142
- http://secunia.com/advisories/54834
- http://www.squid-cache.org/Advisories/SQUID-2013_3.txt
- http://www.squid-cache.org/Versions/v3/3.2/changesets/squid-3.2-11826.patch
- http://www.squid-cache.org/Versions/v3/3.3/changesets/squid-3.3-12591.patch