An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure allows a remote attacker to trigger an assert by sending crafted HTTP/1 requests. The assert will cause an automatic restart with a clean cache, which makes it a Denial of Service attack.
2019-09-03T21:15:10.953
2024-11-21T04:29:40.687
Modified
CVSSv3.0: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:C
10.0
6.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | varnish-software | varnish_cache | < 6.0.4 | Yes |
| Application | varnish_cache_project | varnish_cache | ≤ 6.1.1 | Yes |
| Application | varnish_cache_project | varnish_cache | < 6.2.1 | Yes |
| Operating System | debian | debian_linux | 10.0 | Yes |