CVE-2014-3609
squid: assertion failure in Range header processing (SQUID-2014:2)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
HttpHdrRange.cc in Squid 3.x before 3.3.12 and 3.4.x before 3.4.6 allows remote attackers to cause a denial of service (crash) via a request with crafted "Range headers with unidentifiable byte-range values."
HttpHdrRange.cc en Squid 3.x anterior a 3.3.12 y 3.4.x anterior a 3.4.6 permite a atacantes remotos causar una denegación de servicio (caída) a través de una solicitud con ' cabeceras de rango con valores de rango de bytes no identificables' manipuladas.
A flaw was found in the way Squid handled malformed HTTP Range headers. A remote attacker able to send HTTP requests to the Squid proxy could use this flaw to crash Squid.
Due to incorrect state management, Squid before 3.3.12 is vulnerable to a denial of service attack when processing certain HTTPS requests if the SSL-Bump feature is enabled. Matthew Daley discovered that Squid 3 did not properly perform input validation in request parsing. A remote attacker could send crafted Range requests to cause a denial of service. Due to incorrect buffer management Squid can be caused by an attacker to write outside its allocated SNMP buffer. Due to incorrect bounds checking Squid pinger binary is vulnerable to denial of service or information leak attack when processing larger than normal ICMP or ICMPv6 packets. Due to incorrect input validation Squid pinger binary is vulnerable to denial of service or information leak attacks when processing ICMP or ICMPv6 packets.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-05-14 CVE Reserved
- 2014-08-28 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
- CWE-617: Reachable Assertion
CAPEC
References (16)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/60179 | Third Party Advisory | |
http://secunia.com/advisories/60334 | Third Party Advisory | |
http://secunia.com/advisories/61320 | Third Party Advisory | |
http://secunia.com/advisories/61412 | Third Party Advisory | |
http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.html | X_refsource_confirm |
|
http://www.securityfocus.com/bid/69453 | Vdb Entry | |
http://www.squid-cache.org/Versions/v3/3.0/changesets/squid-3.0-9201.patch | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00025.html | 2017-01-07 | |
http://lists.opensuse.org/opensuse-updates/2014-09/msg00029.html | 2017-01-07 | |
http://rhn.redhat.com/errata/RHSA-2014-1147.html | 2017-01-07 | |
http://www.debian.org/security/2014/dsa-3014 | 2017-01-07 | |
http://www.debian.org/security/2015/dsa-3139 | 2017-01-07 | |
http://www.squid-cache.org/Advisories/SQUID-2014_2.txt | 2017-01-07 | |
http://www.ubuntu.com/usn/USN-2327-1 | 2017-01-07 | |
https://access.redhat.com/security/cve/CVE-2014-3609 | 2014-09-03 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1134209 | 2014-09-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.1 Search vendor "Squid-cache" for product "Squid" and version "3.1" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.1.0.1 Search vendor "Squid-cache" for product "Squid" and version "3.1.0.1" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.1.0.2 Search vendor "Squid-cache" for product "Squid" and version "3.1.0.2" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.1.0.3 Search vendor "Squid-cache" for product "Squid" and version "3.1.0.3" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.1.0.4 Search vendor "Squid-cache" for product "Squid" and version "3.1.0.4" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.1.0.5 Search vendor "Squid-cache" for product "Squid" and version "3.1.0.5" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.1.0.6 Search vendor "Squid-cache" for product "Squid" and version "3.1.0.6" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.1.0.7 Search vendor "Squid-cache" for product "Squid" and version "3.1.0.7" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.1.0.8 Search vendor "Squid-cache" for product "Squid" and version "3.1.0.8" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.1.0.9 Search vendor "Squid-cache" for product "Squid" and version "3.1.0.9" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.1.0.10 Search vendor "Squid-cache" for product "Squid" and version "3.1.0.10" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.1.0.11 Search vendor "Squid-cache" for product "Squid" and version "3.1.0.11" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.1.0.12 Search vendor "Squid-cache" for product "Squid" and version "3.1.0.12" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.1.0.13 Search vendor "Squid-cache" for product "Squid" and version "3.1.0.13" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.1.0.14 Search vendor "Squid-cache" for product "Squid" and version "3.1.0.14" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.1.0.15 Search vendor "Squid-cache" for product "Squid" and version "3.1.0.15" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.1.0.16 Search vendor "Squid-cache" for product "Squid" and version "3.1.0.16" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.1.0.17 Search vendor "Squid-cache" for product "Squid" and version "3.1.0.17" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.1.0.18 Search vendor "Squid-cache" for product "Squid" and version "3.1.0.18" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.1.1 Search vendor "Squid-cache" for product "Squid" and version "3.1.1" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.1.2 Search vendor "Squid-cache" for product "Squid" and version "3.1.2" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.1.3 Search vendor "Squid-cache" for product "Squid" and version "3.1.3" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.1.4 Search vendor "Squid-cache" for product "Squid" and version "3.1.4" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.1.5 Search vendor "Squid-cache" for product "Squid" and version "3.1.5" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.1.5.1 Search vendor "Squid-cache" for product "Squid" and version "3.1.5.1" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.1.6 Search vendor "Squid-cache" for product "Squid" and version "3.1.6" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.1.7 Search vendor "Squid-cache" for product "Squid" and version "3.1.7" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.1.8 Search vendor "Squid-cache" for product "Squid" and version "3.1.8" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.1.9 Search vendor "Squid-cache" for product "Squid" and version "3.1.9" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.1.10 Search vendor "Squid-cache" for product "Squid" and version "3.1.10" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.1.11 Search vendor "Squid-cache" for product "Squid" and version "3.1.11" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.1.12 Search vendor "Squid-cache" for product "Squid" and version "3.1.12" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.1.13 Search vendor "Squid-cache" for product "Squid" and version "3.1.13" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.1.14 Search vendor "Squid-cache" for product "Squid" and version "3.1.14" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.1.15 Search vendor "Squid-cache" for product "Squid" and version "3.1.15" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.2.0.1 Search vendor "Squid-cache" for product "Squid" and version "3.2.0.1" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.2.0.2 Search vendor "Squid-cache" for product "Squid" and version "3.2.0.2" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.2.0.3 Search vendor "Squid-cache" for product "Squid" and version "3.2.0.3" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.2.0.4 Search vendor "Squid-cache" for product "Squid" and version "3.2.0.4" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.2.0.5 Search vendor "Squid-cache" for product "Squid" and version "3.2.0.5" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.2.0.6 Search vendor "Squid-cache" for product "Squid" and version "3.2.0.6" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.2.0.7 Search vendor "Squid-cache" for product "Squid" and version "3.2.0.7" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.2.0.8 Search vendor "Squid-cache" for product "Squid" and version "3.2.0.8" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.2.0.9 Search vendor "Squid-cache" for product "Squid" and version "3.2.0.9" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.2.0.10 Search vendor "Squid-cache" for product "Squid" and version "3.2.0.10" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.2.0.11 Search vendor "Squid-cache" for product "Squid" and version "3.2.0.11" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.2.0.12 Search vendor "Squid-cache" for product "Squid" and version "3.2.0.12" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.2.0.13 Search vendor "Squid-cache" for product "Squid" and version "3.2.0.13" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.2.0.14 Search vendor "Squid-cache" for product "Squid" and version "3.2.0.14" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.2.0.15 Search vendor "Squid-cache" for product "Squid" and version "3.2.0.15" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.2.0.16 Search vendor "Squid-cache" for product "Squid" and version "3.2.0.16" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.2.0.17 Search vendor "Squid-cache" for product "Squid" and version "3.2.0.17" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.2.0.18 Search vendor "Squid-cache" for product "Squid" and version "3.2.0.18" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.2.0.19 Search vendor "Squid-cache" for product "Squid" and version "3.2.0.19" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.2.1 Search vendor "Squid-cache" for product "Squid" and version "3.2.1" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.2.2 Search vendor "Squid-cache" for product "Squid" and version "3.2.2" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.2.3 Search vendor "Squid-cache" for product "Squid" and version "3.2.3" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.2.4 Search vendor "Squid-cache" for product "Squid" and version "3.2.4" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.2.5 Search vendor "Squid-cache" for product "Squid" and version "3.2.5" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.2.6 Search vendor "Squid-cache" for product "Squid" and version "3.2.6" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.2.7 Search vendor "Squid-cache" for product "Squid" and version "3.2.7" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.2.8 Search vendor "Squid-cache" for product "Squid" and version "3.2.8" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.2.9 Search vendor "Squid-cache" for product "Squid" and version "3.2.9" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.2.10 Search vendor "Squid-cache" for product "Squid" and version "3.2.10" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.2.11 Search vendor "Squid-cache" for product "Squid" and version "3.2.11" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.2.12 Search vendor "Squid-cache" for product "Squid" and version "3.2.12" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.3.0 Search vendor "Squid-cache" for product "Squid" and version "3.3.0" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.3.0.2 Search vendor "Squid-cache" for product "Squid" and version "3.3.0.2" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.3.0.3 Search vendor "Squid-cache" for product "Squid" and version "3.3.0.3" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.3.1 Search vendor "Squid-cache" for product "Squid" and version "3.3.1" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.3.2 Search vendor "Squid-cache" for product "Squid" and version "3.3.2" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.3.3 Search vendor "Squid-cache" for product "Squid" and version "3.3.3" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.3.4 Search vendor "Squid-cache" for product "Squid" and version "3.3.4" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.3.5 Search vendor "Squid-cache" for product "Squid" and version "3.3.5" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.3.6 Search vendor "Squid-cache" for product "Squid" and version "3.3.6" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.3.7 Search vendor "Squid-cache" for product "Squid" and version "3.3.7" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.3.8 Search vendor "Squid-cache" for product "Squid" and version "3.3.8" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.3.9 Search vendor "Squid-cache" for product "Squid" and version "3.3.9" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.3.10 Search vendor "Squid-cache" for product "Squid" and version "3.3.10" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.3.11 Search vendor "Squid-cache" for product "Squid" and version "3.3.11" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.4.0.1 Search vendor "Squid-cache" for product "Squid" and version "3.4.0.1" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.4.0.2 Search vendor "Squid-cache" for product "Squid" and version "3.4.0.2" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.4.0.3 Search vendor "Squid-cache" for product "Squid" and version "3.4.0.3" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.4.1 Search vendor "Squid-cache" for product "Squid" and version "3.4.1" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.4.2 Search vendor "Squid-cache" for product "Squid" and version "3.4.2" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.4.3 Search vendor "Squid-cache" for product "Squid" and version "3.4.3" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.4.4 Search vendor "Squid-cache" for product "Squid" and version "3.4.4" | - |
Affected
| ||||||
Squid-cache Search vendor "Squid-cache" | Squid Search vendor "Squid-cache" for product "Squid" | 3.4.5 Search vendor "Squid-cache" for product "Squid" and version "3.4.5" | - |
Affected
|