Back

CRITICAL

Varnish 2.0.6 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator

Published Jan 13, 2010

Description

Varnish 2.0.6 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator. NOTE: the vendor disputes the significance of this report, stating that "This is not a security problem in Varnish or any other piece of software which writes a logfile. The real problem is the mistaken belief that you can cat(1) a random logfile to your terminal safely.

Affected products

Remediation

No remediation recorded yet.

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 13, 2010
Updated Jan 21, 2025
Reserved Dec 30, 2009
CISA Vulnrichment
Updated Jan 21, 2025
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner mitre
Published Jan 13, 2010
Updated Jan 21, 2025
Exploited since n/a
EUVD-2009-4455