CVE-2017-12425

An issue was discovered in Varnish HTTP Cache 4.0.1 through 4.0.4, 4.1.0 through 4.1.7, 5.0.0, and 5.1.0 through 5.1.2. A wrong if statement in the varnishd source code means that particular invalid requests from the client can trigger an assert, related to an Integer Overflow. This causes the varnishd worker process to abort and restart, losing the cached contents in the process. An attacker can therefore crash the varnishd worker process on demand and effectively keep it from serving content - a Denial-of-Service attack. The specific source-code filename containing the incorrect statement varies across releases.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:varnish-cache:varnish:4.0.2:rc-1:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish:4.0.3:rc-1:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish:4.0.3:rc-2:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish:4.0.3:rc-2-proper:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish:4.0.3:rc-3:*:*:*:*:*:*
cpe:2.3:a:varnish_cache_project:varnish_cache:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:varnish_cache_project:varnish_cache:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:varnish_cache_project:varnish_cache:4.0.3:*:*:*:*:*:*:*
cpe:2.3:a:varnish_cache_project:varnish_cache:4.0.4:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:varnish-cache:varnish:4.1.0:*:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.0:beta1:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.0:technology_preview1:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.1:*:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.1:beta1:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.1:beta2:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.2:*:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.2:beta1:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.2:beta2:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.3:*:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.3:beta1:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.3:beta2:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.4:*:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.4:beta1:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.4:beta2:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.4:beta3:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.5:*:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.5:beta1:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.5:beta2:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.6:*:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.7:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:varnish_cache_project:varnish_cache:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:varnish_cache_project:varnish_cache:5.1.0:*:*:*:*:*:*:*
cpe:2.3:a:varnish_cache_project:varnish_cache:5.1.1:*:*:*:*:*:*:*
cpe:2.3:a:varnish_cache_project:varnish_cache:5.1.2:*:*:*:*:*:*:*

History

02 Aug 2022, 19:13

Type Values Removed Values Added
First Time Varnish-software varnish Cache
Varnish-software
CPE cpe:2.3:a:varnish-cache:varnish_cache:4.1.0:beta1:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.3:beta1:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.5:beta2:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.4:beta3:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.4:beta1:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.2:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.3:beta2:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.2:beta2:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.5:beta1:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.6:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.1:beta1:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.5:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.1:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.1:beta2:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.2:beta1:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.4:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.7:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.3:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.4:beta2:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish:4.1.0:tp-1:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.1:beta1:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.1:*:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.6:*:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.3:*:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.5:beta1:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.0:technology_preview1:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.4:beta2:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.4:beta1:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.0:beta1:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.2:*:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.3:beta1:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.5:*:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.4:beta3:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.2:beta1:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.3:beta2:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.7:*:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.1:beta2:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.5:beta2:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.4:*:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_cache:4.1.2:beta2:*:*:*:*:*:*

02 Aug 2022, 16:29

Type Values Removed Values Added
First Time Varnish Cache Project varnish Cache
Varnish Cache Project
CPE cpe:2.3:a:varnish-cache:varnish_cache:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.0.3:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:5.1.1:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.0.4:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:5.1.0:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:5.1.2:*:*:*:*:*:*:*
cpe:2.3:a:varnish_cache_project:varnish_cache:5.1.0:*:*:*:*:*:*:*
cpe:2.3:a:varnish_cache_project:varnish_cache:5.1.1:*:*:*:*:*:*:*
cpe:2.3:a:varnish_cache_project:varnish_cache:4.0.4:*:*:*:*:*:*:*
cpe:2.3:a:varnish_cache_project:varnish_cache:4.0.3:*:*:*:*:*:*:*
cpe:2.3:a:varnish_cache_project:varnish_cache:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:varnish_cache_project:varnish_cache:5.1.2:*:*:*:*:*:*:*
cpe:2.3:a:varnish_cache_project:varnish_cache:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:varnish_cache_project:varnish_cache:5.0.0:*:*:*:*:*:*:*

21 Jun 2022, 16:58

Type Values Removed Values Added
CPE cpe:2.3:a:varnish-cache:varnish:5.1.0:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish:4.1.4:beta1:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish:4.1.7:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish:4.1.4:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish:4.1.5:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish:5.1.2:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish:4.1.3:beta2:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish:4.1.0:beta1:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish:4.1.1:beta2:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish:4.0.4:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish:5.1.1:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish:4.1.4:beta2:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish:4.1.4:beta3:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish:4.0.3:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish:4.1.3:beta1:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish:4.1.2:beta1:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish:4.1.5:beta2:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish:4.1.1:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish:4.1.2:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish:4.1.6:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish:4.1.1:beta1:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish:4.1.3:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish:4.1.2:beta2:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish:4.1.5:beta1:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.0:beta1:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.3:beta1:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:5.1.0:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.5:beta2:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.4:beta3:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:5.1.1:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.4:beta1:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.2:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.3:beta2:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.2:beta2:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.0.4:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.5:beta1:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.4:beta2:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.6:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.1:beta1:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.5:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.1:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.1:beta2:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.0.3:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.4:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.7:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.3:*:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:4.1.2:beta1:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:5.1.2:*:*:*:*:*:*:*
First Time Varnish-cache varnish Cache

Information

Published : 2017-08-04 09:29

Updated : 2023-12-10 12:15


NVD link : CVE-2017-12425

Mitre link : CVE-2017-12425

CVE.ORG link : CVE-2017-12425


JSON object : View

Products Affected

varnish-cache

  • varnish

varnish_cache_project

  • varnish_cache

varnish-software

  • varnish_cache
CWE
CWE-190

Integer Overflow or Wraparound