CVE-2019-15892
03.09.2019, 21:15
An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure allows a remote attacker to trigger an assert by sending crafted HTTP/1 requests. The assert will cause an automatic restart with a clean cache, which makes it a Denial of Service attack.Enginsight
Vendor | Product | Version |
---|---|---|
varnish-software | varnish_cache | 6.0.0 ≤ 𝑥 < 6.0.4 |
varnish_cache_project | varnish_cache | 6.1.0 ≤ 𝑥 ≤ 6.1.1 |
varnish_cache_project | varnish_cache | 6.2.0 ≤ 𝑥 < 6.2.1 |
debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References