Varnish HTTP Request Parsing Denial of Service Vulnerability
BID:33712
Info
Varnish HTTP Request Parsing Denial of Service Vulnerability
| Bugtraq ID: | 33712 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 17 2008 12:00AM |
| Updated: | Feb 12 2009 04:48PM |
| Credit: | Varnish |
| Vulnerable: |
Varnish Varnish 2.0 |
| Not Vulnerable: |
Varnish Varnish 2.0.1 |
Discussion
Varnish HTTP Request Parsing Denial of Service Vulnerability
Varnish is prone to a remote denial-of-service vulnerability because the application fails to handle certain HTTP requests.
Successfully exploiting this issue allows remote attackers to crash the affected application, denying further service to legitimate users.
This issue affects versions prior to Varnish 2.0.1.
Varnish is prone to a remote denial-of-service vulnerability because the application fails to handle certain HTTP requests.
Successfully exploiting this issue allows remote attackers to crash the affected application, denying further service to legitimate users.
This issue affects versions prior to Varnish 2.0.1.
Exploit / POC
Varnish HTTP Request Parsing Denial of Service Vulnerability
An attacker may exploit this issue by using readily available networking tools.
An attacker may exploit this issue by using readily available networking tools.
Solution / Fix
Varnish HTTP Request Parsing Denial of Service Vulnerability
Solution:
The vendor has released updates. Please see the references for more information.
Solution:
The vendor has released updates. Please see the references for more information.
References
Varnish HTTP Request Parsing Denial of Service Vulnerability
References:
References:
- Varnish Project page (Varnish)