← Back

CVE-2017-12425

nvd nist
Published: Aug 4, 2017Modified: May 13, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

An issue was discovered in Varnish HTTP Cache 4.0.1 through 4.0.4, 4.1.0 through 4.1.7, 5.0.0, and 5.1.0 through 5.1.2. A wrong if statement in the varnishd source code means that particular invalid requests from the client can trigger an assert, related to an Integer Overflow. This causes the varnishd worker process to abort and restart, losing the cached contents in the process. An attacker can therefore crash the varnishd worker process on demand and effectively keep it from serving content - a Denial-of-Service attack. The specific source-code filename containing the incorrect statement varies across releases.

Affected (34)

1 product
Varnish
Varnish Cache
Varnish Cache
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Varnish Cache
Version 4.0.2 rc-1
Version 4.0.3 rc-1
Version 4.0.3 rc-2-proper
Version 4.0.3 rc-2
Version 4.0.3 rc-3
Version 4.0.1
Version 4.0.2
Version 4.0.3
Version 4.0.4
Configuration B
21 vulnerable
Vulnerable SoftwareAffected Versions
Version 4.1.0
Varnish Software
Version 4.1.0 beta1
Version 4.1.0 technology_preview1
Version 4.1.1
Version 4.1.1 beta1
Version 4.1.1 beta2
Version 4.1.2
Version 4.1.2 beta1
Version 4.1.2 beta2
Version 4.1.3
Version 4.1.3 beta1
Version 4.1.3 beta2
Version 4.1.4
Version 4.1.4 beta1
Version 4.1.4 beta2
Version 4.1.4 beta3
Version 4.1.5
Version 4.1.5 beta1
Version 4.1.5 beta2
Version 4.1.6
Version 4.1.7
Configuration C
4 vulnerable
Vulnerable SoftwareAffected Versions
Version 5.0.0
Version 5.1.0
Version 5.1.1
Version 5.1.2

References (12)

Source: cve@mitre.org
Issue TrackingThird Party Advisory
Source: cve@mitre.org
Issue TrackingThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.