Squid HTTP header port number processing DoS Vulnerability
Release date:
Updated on: 2013-07-16
Affected Systems:
Squid 3.x
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CCVE-2013-4123
Squid is an efficient Web Cache and proxy program.
Squid 3.2-3.2.12 and 3.3-3.3.7 have errors in handling the port numbers in the "Host" header of the HTTP request. The displayed service is unavailable, causing a denial of service.
<* Source: Saran Neti
Link: http://secunia.com/advisories/54142/
Http://www.squid-cache.org/Advisories/SQUID-2013_3.txt
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Squid
-----
Squid has released a Security Bulletin (SQUID-2013_3) and corresponding patches for this:
SQUID-2013_3: Squid Proxy Cache Security Update Advisory SQUID-2013: 3
Link: http://www.squid-cache.org/Advisories/SQUID-2013_3.txt
Patch download:
Squid 3.2:
Http://www.squid-cache.org/Versions/v3/3.2/changesets/squid-3.2-11826.patch
Squid 3.3:
Http://www.squid-cache.org/Versions/v3/3.3/changesets/squid-3.3-12591.patch