CVE-2017-12425

7.5 HIGH
Published: August 04, 2017 Modified: May 13, 2026
View on NVD

Description

An issue was discovered in Varnish HTTP Cache 4.0.1 through 4.0.4, 4.1.0 through 4.1.7, 5.0.0, and 5.1.0 through 5.1.2. A wrong if statement in the varnishd source code means that particular invalid requests from the client can trigger an assert, related to an Integer Overflow. This causes the varnishd worker process to abort and restart, losing the cached contents in the process. An attacker can therefore crash the varnishd worker process on demand and effectively keep it from serving content - a Denial-of-Service attack. The specific source-code filename containing the incorrect statement varies across releases.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1477222
Source: cve@mitre.org
Issue Tracking Third Party Advisory
https://bugzilla.suse.com/show_bug.cgi?id=1051917
Source: cve@mitre.org
Issue Tracking Third Party Advisory
https://github.com/varnishcache/varnish-cache/issues/2379
Source: cve@mitre.org
Third Party Advisory
https://lists.debian.org/debian-security-announce/2017/msg00186.html
Source: cve@mitre.org
Mailing List Third Party Advisory
http://www.debian.org/security/2017/dsa-3924
Source: af854a3a-2127-422b-91ae-364da2661108
https://bugzilla.redhat.com/show_bug.cgi?id=1477222
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking Third Party Advisory
https://bugzilla.suse.com/show_bug.cgi?id=1051917
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking Third Party Advisory
https://github.com/varnishcache/varnish-cache/issues/2379
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://lists.debian.org/debian-security-announce/2017/msg00186.html
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List Third Party Advisory
https://www.varnish-cache.org/security/VSV00001.html#vsv00001
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

12 reference(s) from NVD

Quick Stats

CVSS v3 Score
7.5 / 10.0
EPSS (Exploit Probability)
2.4%
82th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

varnish-software varnish-cache varnish_cache_project