PT-2012-6067 · Squid+3 · Squid+4

Jan Lieskovsky

·

Published

2012-12-20

·

Updated

2024-06-15

·

CVE-2012-5643

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Squid versions 2.x through 3.1.21 Squid versions 3.2.x through 3.2.3 Squid versions 3.3.x through 3.3.0.1
Description The issue allows remote attackers to cause a denial of service due to memory consumption. This can be achieved through invalid Content-Length headers, long POST requests, or crafted authentication credentials.
Recommendations For Squid versions 2.x through 3.1.21, update to version 3.1.22 or later. For Squid versions 3.2.x through 3.2.3, update to version 3.2.4 or later. For Squid versions 3.3.x through 3.3.0.1, update to version 3.3.0.2 or later.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2013_0505
CVE-2012-5643
DSA-2631-1
OPENSUSE-SU-2024:10307-1
RHSA-2013:0505
RHSA-2013_0505
SUSE-SU-2013_0327-1
SUSE-SU-2013_0327-2
SUSE-SU-2016:2089-1

Affected Products

Centos
Red Hat
Squid
Squid Cache
Suse