PT-2013-1073 · Varnish · Varnish

Tollef Fog Heen

·

Published

2013-11-01

·

Updated

2026-05-11

·

CVE-2013-4484

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Varnish versions prior to 3.0.5
Description The issue allows remote attackers to cause a denial of service, leading to a child-process crash and temporary caching outage. This can be achieved via a GET request with trailing whitespace characters and no URI.
Recommendations For versions prior to 3.0.5, update to version 3.0.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the Varnish service to minimize the risk of exploitation.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-02536
CVE-2013-4484
DSA-2814-1
MGASA-2014-0065
OPENSUSE-SU-2024:10116-1
OPENSUSE-SU-2026:10751-1

Affected Products

Varnish