Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2017-12425 Details

Description

An issue was discovered in Varnish HTTP Cache 4.0.1 through 4.0.4, 4.1.0 through 4.1.7, 5.0.0, and 5.1.0 through 5.1.2. A wrong if statement in the varnishd source code means that particular invalid requests from the client can trigger an assert, related to an Integer Overflow. This causes the varnishd worker process to abort and restart, losing the cached contents in the process. An attacker can therefore crash the varnishd worker process on demand and effectively keep it from serving content - a Denial-of-Service attack. The specific source-code filename containing the incorrect statement varies across releases.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-190Integer Overflow or Wraparound[email protected]

Affected Products

ProductVersions
varnish-cache varnish
4.0.2 rc-1
4.0.3 rc-1
4.0.3 rc-2
4.0.3 rc-2-proper
4.0.3 rc-3

CPE

  • cpe:2.3:a:varnish-cache:varnish:4.0.2:rc-1:*:*:*:*:*:*
  • cpe:2.3:a:varnish-cache:varnish:4.0.3:rc-1:*:*:*:*:*:*
  • cpe:2.3:a:varnish-cache:varnish:4.0.3:rc-2:*:*:*:*:*:*
  • cpe:2.3:a:varnish-cache:varnish:4.0.3:rc-2-proper:*:*:*:*:*:*
  • cpe:2.3:a:varnish-cache:varnish:4.0.3:rc-3:*:*:*:*:*:*
  • cpe:2.3:a:varnish-cache:varnish:4.1.0:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
varnish cache project varnish cache
4.0.1
4.0.2
4.0.3
4.0.4
5.0.0

CPE

  • cpe:2.3:a:varnish_cache_project:varnish_cache:4.0.1:*:*:*:*:*:*:*
  • cpe:2.3:a:varnish_cache_project:varnish_cache:4.0.2:*:*:*:*:*:*:*
  • cpe:2.3:a:varnish_cache_project:varnish_cache:4.0.3:*:*:*:*:*:*:*
  • cpe:2.3:a:varnish_cache_project:varnish_cache:4.0.4:*:*:*:*:*:*:*
  • cpe:2.3:a:varnish_cache_project:varnish_cache:5.0.0:*:*:*:*:*:*:*
  • cpe:2.3:a:varnish_cache_project:varnish_cache:5.1.0:*:*:*:*:*:*:*
  • cpe:2.3:a:varnish_cache_project:varnish_cache:5.1.1:*:*:*:*:*:*:*
  • cpe:2.3:a:varnish_cache_project:varnish_cache:5.1.2:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
varnish-software varnish cache
4.1.0 beta1
4.1.0 technology_preview1
4.1.1
4.1.1 beta1
4.1.1 beta2

CPE

  • cpe:2.3:a:varnish-software:varnish_cache:4.1.0:beta1:*:*:*:*:*:*
  • cpe:2.3:a:varnish-software:varnish_cache:4.1.0:technology_preview1:*:*:*:*:*:*
  • cpe:2.3:a:varnish-software:varnish_cache:4.1.1:*:*:*:*:*:*:*
  • cpe:2.3:a:varnish-software:varnish_cache:4.1.1:beta1:*:*:*:*:*:*
  • cpe:2.3:a:varnish-software:varnish_cache:4.1.1:beta2:*:*:*:*:*:*
  • cpe:2.3:a:varnish-software:varnish_cache:4.1.2:*:*:*:*:*:*:*
  • cpe:2.3:a:varnish-software:varnish_cache:4.1.2:beta1:*:*:*:*:*:*
  • cpe:2.3:a:varnish-software:varnish_cache:4.1.2:beta2:*:*:*:*:*:*
  • cpe:2.3:a:varnish-software:varnish_cache:4.1.3:*:*:*:*:*:*:*
  • cpe:2.3:a:varnish-software:varnish_cache:4.1.3:beta1:*:*:*:*:*:*
  • cpe:2.3:a:varnish-software:varnish_cache:4.1.3:beta2:*:*:*:*:*:*
  • cpe:2.3:a:varnish-software:varnish_cache:4.1.4:*:*:*:*:*:*:*
  • cpe:2.3:a:varnish-software:varnish_cache:4.1.4:beta1:*:*:*:*:*:*
  • cpe:2.3:a:varnish-software:varnish_cache:4.1.4:beta2:*:*:*:*:*:*
  • cpe:2.3:a:varnish-software:varnish_cache:4.1.4:beta3:*:*:*:*:*:*
  • cpe:2.3:a:varnish-software:varnish_cache:4.1.5:*:*:*:*:*:*:*
  • cpe:2.3:a:varnish-software:varnish_cache:4.1.5:beta1:*:*:*:*:*:*
  • cpe:2.3:a:varnish-software:varnish_cache:4.1.5:beta2:*:*:*:*:*:*
  • cpe:2.3:a:varnish-software:varnish_cache:4.1.6:*:*:*:*:*:*:*
  • cpe:2.3:a:varnish-software:varnish_cache:4.1.7:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

61 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2017-12425
NVD Published Date:
Aug 4, 2017
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2017-12425 Details - Not Deferred