Download
| Alert*
oval:org.secpod.oval:def:106965
varnish is installed oval:org.secpod.oval:def:1800433 varnish is installed oval:org.secpod.oval:def:602478 Régis Leroy from Makina Corpus discovered that varnish, a caching HTTP reverse proxy, is vulnerable to HTTP smuggling issues, potentially resulting in cache poisoning or bypassing of access control policies. oval:org.secpod.oval:def:1600424 Varnish 3.x before 3.0.7, when used in certain stacked installations, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a header line terminated by a \r character in conjunction with multiple Content-Length headers in an HTTP request oval:org.secpod.oval:def:1800707 A wrong if statement in the varnishd source code means that synthetic objects in stevedores which over-allocate, may leak up to page size of data from a malloc memory allocation.In a unpredictable percentage of the cases where this condition arises, a segmentation fault will happen instead. All the ... oval:org.secpod.oval:def:108679 This is Varnish Cache, a high-performance HTTP accelerator oval:org.secpod.oval:def:601362 varnish is installed oval:org.secpod.oval:def:601166 A denial of service vulnerability was reported in varnish, a state of the art, high-performance web accelerator. With some configurations of varnish a remote attacker could mount a denial of service via a GET request with trailing whitespace characters and no URI. oval:org.secpod.oval:def:117940 This is Varnish Cache, a high-performance HTTP accelerator. Varnish Cache stores web pages in memory so web servers dont have to create the same web page over and over again. Varnish Cache serves pages much faster than any application server; giving the website a significant speed up. Documentation ... oval:org.secpod.oval:def:117938 This is Varnish Cache, a high-performance HTTP accelerator. Varnish Cache stores web pages in memory so web servers dont have to create the same web page over and over again. Varnish Cache serves pages much faster than any application server; giving the website a significant speed up. Documentation ... oval:org.secpod.oval:def:504702 Varnish Cache is a high-performance HTTP accelerator. It stores web pages in memory so web servers don"t have to create the same web page over and over again, giving the website a significant speed up. The following packages have been upgraded to a later upstream version: varnish . Security Fix: * ... oval:org.secpod.oval:def:507421 Varnish Cache is a high-performance HTTP accelerator. It stores web pages in memory so web servers don"t have to create the same web page over and over again, giving the website a significant speed up. Security Fix: * varnish: Request Forgery Vulnerability For more details about the security issue, ... oval:org.secpod.oval:def:610365 Martin van Kervel Smedshammer discovered that varnish, a state of the art, high-performance web accelerator, is prone to a HTTP/2 request forgery vulnerability. See https://varnish-cache.org/security/VSV00011.html for details. oval:org.secpod.oval:def:507418 Varnish Cache is a high-performance HTTP accelerator. It stores web pages in memory so web servers don"t have to create the same web page over and over again, giving the website a significant speed up. Security Fix: * varnish: Request Forgery Vulnerability For more details about the security issue, ... oval:org.secpod.oval:def:68293 A denial of service vulnerability was discovered in Varnish, a state of the art, high-performance web accelerator. Specially crafted HTTP requests can cause the Varnish daemon to assert and restart, clearing the cache in the process. oval:org.secpod.oval:def:113053 This is Varnish Cache, a high-performance HTTP accelerator. Varnish Cache stores web pages in memory so web servers don't have to create the same web page over and over again. Varnish Cache serves pages much faster than any application server; giving the website a significant speed up. Documenta ... oval:org.secpod.oval:def:113054 This is Varnish Cache, a high-performance HTTP accelerator. Varnish Cache stores web pages in memory so web servers dont have to create the same web page over and over again. Varnish Cache serves pages much faster than any application server; giving the website a significant speed up. Documentation ... oval:org.secpod.oval:def:1800500 A wrong if statement in the varnishd source code means that synthetic objects in stevedores which over-allocate, may leak up to page size of data from a malloc memory allocation.In a unpredictable percentage of the cases where this condition arises, a segmentation fault will happen instead. All the ... oval:org.secpod.oval:def:113581 This is Varnish Cache, a high-performance HTTP accelerator. Varnish Cache stores web pages in memory so web servers dont have to create the same web page over and over again. Varnish Cache serves pages much faster than any application server; giving the website a significant speed up. Documentation ... oval:org.secpod.oval:def:603172 "shamger" and Carlo Cannas discovered that a programming error in Varnish, a state of the art, high-performance web accelerator, may result in disclosure of memory contents or denial of service. See https://varnish-cache.org/security/VSV00002.html for details. oval:org.secpod.oval:def:113499 This is Varnish Cache, a high-performance HTTP accelerator. Varnish Cache stores web pages in memory so web servers dont have to create the same web page over and over again. Varnish Cache serves pages much faster than any application server; giving the website a significant speed up. Documentation ... oval:org.secpod.oval:def:53184 "shamger" and Carlo Cannas discovered that a programming error in Varnish, a state of the art, high-performance web accelerator, may result in disclosure of memory contents or denial of service. See https://varnish-cache.org/security/VSV00002.html for details. oval:org.secpod.oval:def:1800566 A wrong if statement in the varnishd source code means that synthetic objects in stevedores which over-allocate, may leak up to page size of data from a malloc memory allocation.In a unpredictable percentage of the cases where this condition arises, a segmentation fault will happen instead. All the ... oval:org.secpod.oval:def:113526 This is Varnish Cache, a high-performance HTTP accelerator. Varnish Cache stores web pages in memory so web servers don't have to create the same web page over and over again. Varnish Cache serves pages much faster than any application server; giving the website a significant speed up. Documenta ... oval:org.secpod.oval:def:1800432 A wrong if statement in the varnishd source code means that synthetic objects in stevedores which over-allocate, may leak up to page size of data from a malloc memory allocation.In a unpredictable percentage of the cases where this condition arises, a segmentation fault will happen instead. All the ... oval:org.secpod.oval:def:3301079 SUSE Security Update: Security update for varnish oval:org.secpod.oval:def:3300343 SUSE Security Update: Security update for varnish oval:org.secpod.oval:def:1506229 varnish [6.0.8-2.1] - Resolves: #2142092 - CVE-2022-45060 varnish:6/varnish: Request Forgery Vulnerability [6.0.8-2] - Resolves: #2047650 - CVE-2022-23959 varnish:6/varnish: Varnish HTTP/1 Request Smuggling Vulnerability varnish-modules [0.15.0-6] - Related: #1982862 - rebuild for new varnish versio ... oval:org.secpod.oval:def:1506279 [6.6.2-2.1] - Resolves: #2142095 - CVE-2022-45060 varnish: Request Forgery Vulnerability oval:org.secpod.oval:def:120498 This is Varnish Cache, a high-performance HTTP accelerator. Varnish Cache stores web pages in memory so web servers dont have to create the same web page over and over again. Varnish Cache serves pages much faster than any application server; giving the website a significant speed up. Documentation ... oval:org.secpod.oval:def:120494 This is Varnish Cache, a high-performance HTTP accelerator. Varnish Cache stores web pages in memory so web servers dont have to create the same web page over and over again. Varnish Cache serves pages much faster than any application server; giving the website a significant speed up. Documentation ... oval:org.secpod.oval:def:2003845 An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when communication with a TLS termination proxy uses PROXY version 2. There can be an assertion failure and daemon restart, which causes a performance loss. oval:org.secpod.oval:def:88540 varnish: state of the art, high-performance web accelerator Details: USN-5474-1 fixed vulnerabilities in Varnish Cache. Unfortunately the fix for CVE-2020-11653 was incomplete. This update fixes the problem. Original advisory Varnish Cache could be made to restart if it received specially crafted in ... oval:org.secpod.oval:def:707686 varnish: state of the art, high-performance web accelerator Details: USN-5474-1 fixed vulnerabilities in Varnish Cache. Unfortunately the fix for CVE-2020-11653 was incomplete. This update fixes the problem. Original advisory Varnish Cache could be made to restart if it received specially crafted in ... oval:org.secpod.oval:def:1600064 Varnish before 3.0.5 allows remote attackers to cause a denial of service via a GET request with trailing whitespace characters and no URI.varnish 3.0.3 uses world-readable permissions for the /var/log/varnish/ directory and the log files in the directory, which allows local users to obtain sensiti ... oval:org.secpod.oval:def:106964 This is Varnish Cache, a high-performance HTTP accelerator oval:org.secpod.oval:def:106968 This is Varnish Cache, a high-performance HTTP accelerator oval:org.secpod.oval:def:3300695 SUSE Security Update: Security update for varnish oval:org.secpod.oval:def:4500733 Varnish Cache is a high-performance HTTP accelerator. It stores web pages in memory so web servers don"t have to create the same web page over and over again, giving the website a significant speed up. Security Fix: * varnish: Request Forgery Vulnerability For more details about the security issue, ... oval:org.secpod.oval:def:89335 Martin van Kervel Smedshammer discovered that varnish, a state of the art, high-performance web accelerator, is prone to a HTTP/2 request forgery vulnerability. See https://varnish-cache.org/security/VSV00011.html for details. oval:org.secpod.oval:def:2600118 Varnish Cache is a high-performance HTTP accelerator. It stores web pages in memory so web servers don"t have to create the same web page over and over again, giving the website a significant speed up. oval:org.secpod.oval:def:4501096 Varnish Cache is a high-performance HTTP accelerator. It stores web pages in memory so web servers don"t have to create the same web page over and over again, giving the website a significant speed up. Security Fix: * varnish: Request Forgery Vulnerability For more details about the security issue, ... oval:org.secpod.oval:def:88539 varnish: state of the art, high-performance web accelerator Several security issues were fixed in Varnish Cache. oval:org.secpod.oval:def:2500597 Varnish Cache is a high-performance HTTP accelerator. It stores web pages in memory so web servers don"t have to create the same web page over and over again, giving the website a significant speed up. oval:org.secpod.oval:def:4501278 Varnish Cache is a high-performance HTTP accelerator. It stores web pages in memory so web servers don"t have to create the same web page over and over again, giving the website a significant speed up. Security Fix: * varnish: HTTP/2 request smuggling attack via a large Content-Length header for a P ... oval:org.secpod.oval:def:2500474 Varnish Cache is a high-performance HTTP accelerator. It stores web pages in memory so web servers don"t have to create the same web page over and over again, giving the website a significant speed up. oval:org.secpod.oval:def:604510 Alf-Andre Walla discovered a remotely triggerable assert in the Varnish web accelerator; sending a malformed HTTP request could result in denial of service. The oldstable distribution is not affected. oval:org.secpod.oval:def:69750 Alf-Andre Walla discovered a remotely triggerable assert in the Varnish web accelerator; sending a malformed HTTP request could result in denial of service. The oldstable distribution is not affected. oval:org.secpod.oval:def:68003 Varnish Cache is a high-performance HTTP accelerator. It stores web pages in memory so web servers don"t have to create the same web page over and over again, giving the website a significant speed up. The following packages have been upgraded to a later upstream version: varnish . Security Fix: * ... oval:org.secpod.oval:def:2500154 Varnish Cache is a high-performance HTTP accelerator. It stores web pages in memory so web servers don"t have to create the same web page over and over again, giving the website a significant speed up. oval:org.secpod.oval:def:1507107 [6.6.2-3.el9_2.1] - Add parameters h2_rst_allowance and h2_rst_allowance_period to mitigate CVE-2023-44487 - Resolves: RHEL-12818 oval:org.secpod.oval:def:1507109 varnish [6.0.8-3.1] - Add parameters h2_rst_allowance and h2_rst_allowance_period to mitigate CVE-2023-44487 varnish-modules |