[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 3208-1] varnish security update

Debian LTS Advisory DLA-3208-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                      Markus Koschany
November 27, 2022                             https://wiki.debian.org/LTS

Package        : varnish
Version        : 6.1.1-1+deb10u4
CVE ID         : CVE-2020-11653 CVE-2022-45060
Debian Bug     : 956307 1023751

Martin van Kervel Smedshammer discovered a request forgery attack can be
performed on Varnish Cache servers that have the HTTP/2 protocol turned on. An
attacker may introduce characters through the HTTP/2 pseudo-headers that are
invalid in the context of an HTTP/1 request line, causing the Varnish server to
produce invalid HTTP/1 requests to the backend. This may in turn be used to
successfully exploit vulnerabilities in a server behind the Varnish server.

For Debian 10 buster, these problems have been fixed in version

We recommend that you upgrade your varnish packages.

For the detailed security status of varnish please refer to
its security tracker page at:

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Attachment: signature.asc
Description: This is a digitally signed message part

Reply to: