varnish: denial of service handling certain crafted HTTP/1 requests
Published Sep 3, 2019
7.5
HIGHCVSS 3.0
EPSS 5.79%
Description
An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure allows a remote attacker to trigger an assert by sending crafted HTTP/1 requests. The assert will cause an automatic restart with a clean cache, which makes it a Denial of Service attack.
Affected products
No data.
Configuration 1
- ≥ 6.0.0 · < 6.0.4
- ≥ 6.1.0 · ≤ 6.1.1
- ≥ 6.2.0 · < 6.2.1
Configuration 2
- 10.0
No data.
Red Hat Enterprise Linux 8
varnish:6-8030020200530080205.30b713e6
Fixed · RHSA-2020:4756
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-varnish6-0:4.1-6.el7
Fixed · RHEA-2020:2262
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-varnish6-varnish-0:6.0.6-1.el7
Fixed · RHEA-2020:2262
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-varnish6-varnish-modules-0:0.15.0-6.el7
Fixed · RHEA-2020:2262
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-varnish6-0:4.1-6.el7
Fixed · RHEA-2020:2262
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-varnish6-varnish-0:6.0.6-1.el7
Fixed · RHEA-2020:2262
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-varnish6-varnish-modules-0:0.15.0-6.el7
Fixed · RHEA-2020:2262
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-varnish6-0:4.1-6.el7
Fixed · RHEA-2020:2262
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-varnish6-varnish-0:6.0.6-1.el7
Fixed · RHEA-2020:2262
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-varnish6-varnish-modules-0:0.15.0-6.el7
Fixed · RHEA-2020:2262
Red Hat Software Collections
rh-varnish5-varnish
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | varnish:6-8030020200530080205.30b713e6 | Fixed | RHSA-2020:4756 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-varnish6-0:4.1-6.el7 | Fixed | RHEA-2020:2262 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-varnish6-varnish-0:6.0.6-1.el7 | Fixed | RHEA-2020:2262 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-varnish6-varnish-modules-0:0.15.0-6.el7 | Fixed | RHEA-2020:2262 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-varnish6-0:4.1-6.el7 | Fixed | RHEA-2020:2262 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-varnish6-varnish-0:6.0.6-1.el7 | Fixed | RHEA-2020:2262 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-varnish6-varnish-modules-0:0.15.0-6.el7 | Fixed | RHEA-2020:2262 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-varnish6-0:4.1-6.el7 | Fixed | RHEA-2020:2262 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-varnish6-varnish-0:6.0.6-1.el7 | Fixed | RHEA-2020:2262 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-varnish6-varnish-modules-0:0.15.0-6.el7 | Fixed | RHEA-2020:2262 |
| Red Hat Software Collections | rh-varnish5-varnish | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This is a remote denial of service flaw in varnish cache application. It causes varnish to restart, with a clean cache, since the purpose of varnish is to cache web pages thereby improving overall web server performance, an attacker can cause web performance to degrade due to this attack.
Red Hat mitigation
This flaw can be mitigated by using making changes in varnish configuration by using VCL (Varnish Configuration Language). More details available at: https://varnish-cache.org/security/VSV00003-mitigation.html#vsv00003-mitigation
References (13)
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00069.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00089.html vendor-advisoryx_refsource_SUSE
- https://access.redhat.com/security/cve/CVE-2019-15892 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1756079 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-6803 Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3OEOCYRU43TWEU2C65F3D6GK64MSWNNK/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DBAQF6UDRSTURGINIMSMLJR4PTDYWA7C/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KLSF54TDJWJLINIFEW5V5BKDNY5EQRR3/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-15892
- https://seclists.org/bugtraq/2019/Sep/5 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://varnish-cache.org/security/VSV00003.html x_refsource_MISCVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-15892
- https://www.debian.org/security/2019/dsa-4514 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.