CVE-2019-15892

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/09/2019
Last modified:
07/11/2023

Description

An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure allows a remote attacker to trigger an assert by sending crafted HTTP/1 requests. The assert will cause an automatic restart with a clean cache, which makes it a Denial of Service attack.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:varnish-software:varnish_cache:*:*:*:*:lts:*:*:* 6.0.0 (including) 6.0.4 (excluding)
cpe:2.3:a:varnish_cache_project:varnish_cache:*:*:*:*:*:*:*:* 6.1.0 (including) 6.1.1 (including)
cpe:2.3:a:varnish_cache_project:varnish_cache:*:*:*:*:*:*:*:* 6.2.0 (including) 6.2.1 (excluding)
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*