CVE-2014-3609

Publication date 28 August 2014

Last updated 24 July 2024


Ubuntu priority

HttpHdrRange.cc in Squid 3.x before 3.3.12 and 3.4.x before 3.4.6 allows remote attackers to cause a denial of service (crash) via a request with crafted "Range headers with unidentifiable byte-range values."

Status

Package Ubuntu Release Status
squid3 14.04 LTS trusty
Fixed 3.3.8-1ubuntu6.1
12.04 LTS precise
Fixed 3.1.19-1ubuntu3.12.04.3
10.04 LTS lucid Ignored end of life

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
squid3

References

Related Ubuntu Security Notices (USN)

Other references