Vulnerability record · CVE-2017-12425 · published 4 August 2017
CVE-2017-12425: Varnish-cache varnish integer overflow vulnerability
Varnish Cache · Varnish
An issue was discovered in Varnish HTTP Cache 4.0.1 through 4.0.4, 4.1.0 through 4.1.7, 5.0.0, and 5.1.0 through 5.1.2. A wrong if statement in the varnishd source code means that particular invalid requests from the client can trigger an assert, related to an Integer Overflow. This causes the varnishd worker process to abort and restart, losing the cached contents in the process. An attacker can therefore crash the varnishd worker process on demand and effectively keep it from serving content - a Denial-of-Service attack. The specific source-code filename containing the incorrect statement varies across releases.
Description
An issue was discovered in Varnish HTTP Cache 4.0.1 through 4.0.4, 4.1.0 through 4.1.7, 5.0.0, and 5.1.0 through 5.1.2. A wrong if statement in the varnishd source code means that particular invalid requests from the client can trigger an assert, related to an Integer Overflow. This causes the varnishd worker process to abort and restart, losing the cached contents in the process. An attacker can therefore crash the varnishd worker process on demand and effectively keep it from serving content - a Denial-of-Service attack. The specific source-code filename containing the incorrect statement varies across releases.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.debian.org/security/2017/dsa-3924 | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1477222 | Issue TrackingThird Party Advisory |
| https://bugzilla.suse.com/show_bug.cgi?id=1051917 | Issue TrackingThird Party Advisory |
| https://github.com/varnishcache/varnish-cache/issues/2379 | Third Party Advisory |
| https://lists.debian.org/debian-security-announce/2017/msg00186.html | Mailing ListThird Party Advisory |
| https://www.varnish-cache.org/security/VSV00001.html#vsv00001 | Vendor Advisory |
| http://www.debian.org/security/2017/dsa-3924 | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1477222 | Issue TrackingThird Party Advisory |
| https://bugzilla.suse.com/show_bug.cgi?id=1051917 | Issue TrackingThird Party Advisory |
| https://github.com/varnishcache/varnish-cache/issues/2379 | Third Party Advisory |
| https://lists.debian.org/debian-security-announce/2017/msg00186.html | Mailing ListThird Party Advisory |
| https://www.varnish-cache.org/security/VSV00001.html#vsv00001 | Vendor Advisory |
Track CVE-2017-12425 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-12425), CISA KEV, FIRST EPSS (scores of 2026-10-02). This page is refreshed as NVD updates the record.