CVE-2015-8852
25.04.2016, 14:59
Varnish 3.x before 3.0.7, when used in certain stacked installations, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a header line terminated by a \r (carriage return) character in conjunction with multiple Content-Length headers in an HTTP request.Enginsight
Vendor | Product | Version |
---|---|---|
varnish_cache_project | varnish_cache | 3.0.0:beta1 |
varnish_cache_project | varnish_cache | 3.0.0:beta2 |
varnish_cache_project | varnish_cache | 3.0.1 |
varnish_cache_project | varnish_cache | 3.0.2 |
varnish_cache_project | varnish_cache | 3.0.3 |
varnish_cache_project | varnish_cache | 3.0.4 |
varnish_cache_project | varnish_cache | 3.0.5 |
varnish_cache_project | varnish_cache | 3.0.6 |
debian | debian_linux | 7.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References