Description
This vulnerability allows remote attackers to deny service on vulnerable installations of The Squid Software Foundation Squid 3.5.27-20180318. Authentication is not required to exploit this vulnerability. The specific flaw exists within ClientRequestContext::sslBumpAccessCheck(). A crafted request can trigger the dereference of a null pointer. An attacker can leverage this vulnerability to create a denial-of-service condition to users of the system. Was ZDI-CAN-6088.
In plain language
AI Worth attentionIf you run Squid 3.5.27-20180318, a remote attacker may be able to crash it with a specially crafted request—so it’s worth acting, even though it’s a medium-severity issue.
In The Squid Software Foundation Squid, an unauthenticated remote denial-of-service is possible via a crafted request that triggers a null-pointer dereference in ClientRequestContext::sslBumpAccessCheck(), crashing or freezing the proxy process.
What to do now
- Check whether your system is running Squid version 3.5.27-20180318.
- If you are on that version, review the vendor advisory at SQUID-2018_3 and plan an upgrade to the fixed Squid release referenced there.
- After upgrading, restart Squid and test that normal proxying (including any SSL bumping use) works as expected.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:NConfidentialityI:NIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2018-1172 and every CVE in our database. Create a free account — no credit card required.
Create Free Account