Bug 830319 (CVE-2013-4123) - VUL-0: CVE-2013-4123: squid: SQUID-2013:3 Denial of service in request processing
Summary: VUL-0: CVE-2013-4123: squid: SQUID-2013:3 Denial of service in request proces...
Status: RESOLVED FIXED
Alias: CVE-2013-4123
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Deadline: 2013-08-08
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: maint:running:53765:moderate
Keywords:
Depends on:
Blocks:
 
Reported: 2013-07-19 12:07 UTC by Marcus Meissner
Modified: 2016-04-27 19:28 UTC (History)
1 user (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2013-07-19 12:07:44 UTC
public via squid

CVE-2013-4123

Squid web proxy version 3.2 up to and including 3.2.12 and 3.3 up to 
including 3.3.7 are vulnerable to a denialof service attack from any 
client able to generate crafted HTTP requests.

References:
http://www.squid-cache.org/Advisories/SQUID-2013_3.txt
  http://www.squid-cache.org/Versions/v3/3.2/changesets/squid-3.2-11826.patch
  http://www.squid-cache.org/Versions/v3/3.3/changesets/squid-3.3-12591.patch

PS. for preview replace "www" with "master" in the official links above. 
There is no embargo.

Amos Jeffries
Squid Project
Comment 1 Swamp Workflow Management 2013-07-19 22:00:26 UTC
bugbot adjusting priority
Comment 2 Swamp Workflow Management 2013-07-25 14:28:29 UTC
The SWAMPID for this issue is 53765.
This issue was rated as moderate.
Please submit fixed packages until 2013-08-08.
When done, please reassign the bug to security-team@suse.de.
Patchinfo will be handled by security team.
Comment 4 Roman Drahtmueller 2013-08-22 09:17:56 UTC
sle* squid,squid3 packages are unaffected.
Comment 5 Bernhard Wiedemann 2013-08-30 15:02:03 UTC
This is an autogenerated message for OBS integration:
This bug (830319) was mentioned in
https://build.opensuse.org/request/show/196904 12.3 / squid
Comment 6 Bernhard Wiedemann 2013-08-30 16:00:48 UTC
This is an autogenerated message for OBS integration:
This bug (830319) was mentioned in
https://build.opensuse.org/request/show/196915 12.3 / squid
Comment 7 Bernhard Wiedemann 2013-08-30 16:01:50 UTC
This is an autogenerated message for OBS integration:
This bug (830319) was mentioned in
https://build.opensuse.org/request/show/196913 Maintenance /
Comment 8 Roman Drahtmueller 2013-08-30 16:04:09 UTC
Affected is only the package named "squid" in openSUSE-12.3, which is of version 3.2.11.
Fix also comes with fix for concurrent/independent bug bnc#829084.
Package submitted, revoked and re-submitted. Twice. The one revoked. Short: There's only one...

Reassigning to security-team@suse.de for shipping+handling.
Comment 9 Swamp Workflow Management 2013-09-13 08:05:03 UTC
openSUSE-SU-2013:1435-1: An update that solves two vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 677335,829084,830319
CVE References: CVE-2013-4115,CVE-2013-4123
Sources used:
openSUSE 12.3 (src):    squid-3.2.11-3.8.1
Comment 10 Marcus Meissner 2013-10-25 18:02:22 UTC
done