PT-2019-3468 · Varnish+4 · Varnish Cache+4

Alf-Andre Walla

·

Published

2019-09-03

·

Updated

2026-05-11

·

CVE-2019-15892

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Varnish Cache versions prior to 6.0.4 LTS Varnish Cache versions 6.1.x through 6.2.0
Description An issue in Varnish Cache allows a remote attacker to trigger an assert by sending crafted HTTP/1 requests, causing an automatic restart with a clean cache and resulting in a Denial of Service attack. The issue is due to insufficient input validation in the HTTP/1 parser.
Recommendations For Varnish Cache versions prior to 6.0.4 LTS, update to version 6.0.4 LTS or later. For Varnish Cache versions 6.1.x through 6.2.0, update to version 6.2.1 or later. As a temporary workaround, consider restricting access to the HTTP/1 parser to minimize the risk of exploitation.

Fix

DoS

RCE

Assertion Failure

Weakness Enumeration

Related Identifiers

BDU:2019-03642
CESA-2020_4756
CVE-2019-15892
DSA-4514-1
OESA-2021-1032
OPENSUSE-SU-2019:2184-1
OPENSUSE-SU-2019:2221-1
OPENSUSE-SU-2019_2184-1
OPENSUSE-SU-2024:11493-1
OPENSUSE-SU-2026:10751-1
RHSA-2020:4756
RHSA-2020_4756
RLSA-2020:4756

Affected Products

Centos
Red Hat
Rocky Linux
Suse
Varnish Cache