CVE Tools

Description

This vulnerability allows remote attackers to deny service on vulnerable installations of The Squid Software Foundation Squid 3.5.27-20180318. Authentication is not required to exploit this vulnerability. The specific flaw exists within ClientRequestContext::sslBumpAccessCheck(). A crafted request can trigger the dereference of a null pointer. An attacker can leverage this vulnerability to create a denial-of-service condition to users of the system. Was ZDI-CAN-6088.

In plain language

AI Worth attention

If you run Squid 3.5.27-20180318, a remote attacker may be able to crash it with a specially crafted request—so it’s worth acting, even though it’s a medium-severity issue.

Executive summary

In The Squid Software Foundation Squid, an unauthenticated remote denial-of-service is possible via a crafted request that triggers a null-pointer dereference in ClientRequestContext::sslBumpAccessCheck(), crashing or freezing the proxy process.

If affected, business impact
Web proxy downtimeService disruption for customersIntermittent connectivity failuresPotential loss of productivity

What to do now

  1. Check whether your system is running Squid version 3.5.27-20180318.
  2. If you are on that version, review the vendor advisory at SQUID-2018_3 and plan an upgrade to the fixed Squid release referenced there.
  3. After upgrading, restart Squid and test that normal proxying (including any SSL bumping use) works as expected.
Patch / advisory Some work to apply

CVSS Vector Breakdown

AV:NAC:HPR:NUI:NS:UC:NI:NA:H
Exploitability
AV:NAttack Vector
Network
AC:HAttack Complexity
High
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:NConfidentiality
None
I:NIntegrity
None
A:HAvailability
High

Weaknesses

Affected Products

Exploitability

Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

2 techniques
Impact
Initial Access
View detailed technique mapping

References

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2018-1172 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store