Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia 7: MGASA-2020-0154 Critical: Varnish Restart Issue

mageia
Calendar Grey April 2, 2020
Dist Mageia Esm H88
The latest varnish updates mitigate a security vulnerability that results in unexpected restarts and potential cache depletion for TLS proxy configurations.
Updated varnish packages fix security vulnerability: An assert can be triggered in Varnish Cache when using Varnish with a TLS termination proxy, and the proxy and Varnish use the...

Summary

Updated varnish packages fix security vulnerability: An assert can be triggered in Varnish Cache when using Varnish with a TLS termination proxy, and the proxy and Varnish use the PROXY version 2. The assert will cause Varnish to restart, and the cache will be empty after the

References

- https://bugs.mageia.org/show_bug.cgi?id=26404

- https://vinyl-cache.org/security/VSV00005.html

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/FWJNWSLEZGPJBSBKJBLCPFOAO36PCZ7N/

Resolution

SRPMS

- 7/core/varnish-6.3.2-1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 02 Apr 2020
URL: https://advisories.mageia.org/MGASA-2020-0154.html
Type: security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here