MGASA-2020-0154 - Updated varnish packages fix security vulnerability

Publication date: 02 Apr 2020
URL: https://advisories.mageia.org/MGASA-2020-0154.html
Type: security
Affected Mageia releases: 7

Updated varnish packages fix security vulnerability:

An assert can be triggered in Varnish Cache when using Varnish with a TLS
termination proxy, and the proxy and Varnish use the PROXY version 2. The
assert will cause Varnish to restart, and the cache will be empty after the
restart (VSV00005).

References:
- https://bugs.mageia.org/show_bug.cgi?id=26404
- https://varnish-cache.org/security/VSV00005.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/FWJNWSLEZGPJBSBKJBLCPFOAO36PCZ7N/

SRPMS:
- 7/core/varnish-6.3.2-1.mga7

Mageia 2020-0154: varnish security update

Updated varnish packages fix security vulnerability: An assert can be triggered in Varnish Cache when using Varnish with a TLS termination proxy, and the proxy and Varnish use the...

Summary

Updated varnish packages fix security vulnerability: An assert can be triggered in Varnish Cache when using Varnish with a TLS termination proxy, and the proxy and Varnish use the PROXY version 2. The assert will cause Varnish to restart, and the cache will be empty after the

References

- https://bugs.mageia.org/show_bug.cgi?id=26404

- https://varnish-cache.org/security/VSV00005.html

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/FWJNWSLEZGPJBSBKJBLCPFOAO36PCZ7N/

Resolution

MGASA-2020-0154 - Updated varnish packages fix security vulnerability

SRPMS

- 7/core/varnish-6.3.2-1.mga7

Severity
Publication date: 02 Apr 2020
URL: https://advisories.mageia.org/MGASA-2020-0154.html
Type: security

Related News