CVE-2017-12425
An issue was discovered in Varnish HTTP Cache 4.0.1 through 4.0.4, 4.1.0 through 4.1.7, 5.0.0, and 5.1.0 through 5.1.2. A wrong if statement in the varnishd source code means that particular invalid requests from the client can trigger an assert, related to an Integer Overflow. This causes the varnishd worker process to abort and restart, losing the cached contents in the process. An attacker can therefore crash the varnishd worker process on demand and effectively keep it from serving content - a Denial-of-Service attack. The specific source-code filename containing the incorrect statement varies across releases.
Published:Aug 2, 2017
Last Modified:Apr 20, 2025
EPS:Aug 4, 2017
EPSS Score:0.00823
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Varnish-cache
Product
Varnish
Varnish-cache
Varnish
Vendor
Varnish-software
Product
Varnish Cache
Varnish-software
Varnish Cache
Vendor
Varnish Cache Project
Product
Varnish Cache
Varnish Cache Project
Varnish Cache
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
