rpm package
opensuse/varnish&distro=openSUSE Leap 15.1
pkg:rpm/opensuse/varnish&distro=openSUSE%20Leap%2015.1
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2019-20637 | — | < 6.2.1-lp151.3.6.1 | 6.2.1-lp151.3.6.1 | Apr 8, 2020 | An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclos | ||
| CVE-2020-11653 | — | < 6.2.1-lp151.3.6.1 | 6.2.1-lp151.3.6.1 | Apr 8, 2020 | An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when communication with a TLS termination proxy uses PROXY version 2. There can be an assertion failure and daemon restart, which causes a performance loss. | ||
| CVE-2019-15892 | — | < 6.2.1-lp151.3.3.1 | 6.2.1-lp151.3.3.1 | Sep 3, 2019 | An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure allows a remote attacker to trigger an assert by sending crafted HTTP/1 requests. The assert will cause an automatic restart with a clean cache, which makes it a |
- CVE-2019-20637Apr 8, 2020affected < 6.2.1-lp151.3.6.1fixed 6.2.1-lp151.3.6.1
An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclos
- CVE-2020-11653Apr 8, 2020affected < 6.2.1-lp151.3.6.1fixed 6.2.1-lp151.3.6.1
An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when communication with a TLS termination proxy uses PROXY version 2. There can be an assertion failure and daemon restart, which causes a performance loss.
- CVE-2019-15892Sep 3, 2019affected < 6.2.1-lp151.3.3.1fixed 6.2.1-lp151.3.3.1
An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure allows a remote attacker to trigger an assert by sending crafted HTTP/1 requests. The assert will cause an automatic restart with a clean cache, which makes it a