Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Mageia 8: MGASA-2022-0079 Critical: Varnish HTTP/1 Request Smuggling

mageia
Calendar Grey February 22, 2022
Dist Mageia Esm H88
The latest patch for Nginx security MGASA-2022-0080 resolves an urgent vulnerability in HTTP/2 streams. Please upgrade immediately.
In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, req...

Summary

In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, request smuggling can occur for HTTP/1 connections. (CVE-2022-23959)

References

- https://bugs.mageia.org/show_bug.cgi?id=30048

- https://lists.debian.org/debian-lts-announce/2022/02/msg00014.html

- https://docs.varnish-software.com/security/VSV00008/

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/UMMDMQWNAE3BTSZUHXQHVAMZC5TLHLYT/

- https://www.cve.org/CVERecord?id=CVE-2022-23959

Resolution

SRPMS

- 8/core/varnish-6.5.1-1.2.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 22 Feb 2022
URL: https://advisories.mageia.org/MGASA-2022-0079.html
Type: security
CVE: CVE-2022-23959

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here