Reachable Assertion in Varnish Cache - #VU25016

 

Reachable Assertion in Varnish Cache - #VU25016

Published: February 7, 2020


Vulnerability identifier: #VU25016
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-617
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a reachable assertion. when using Varnish with a TLS termination proxy, and the proxy and Varnish use the PROXY version 2 protocol to communicate connection details. A remote attacker can send a specially crafted request to the server, cause assertion failure and restart the application, resulting in denial of service condition.


Affected software

Varnish Cache

Remediation

Install updates from vendor's website.

Varnish Cache - addressed in versions 6.0.6, 6.2.3, 6.3.2

External References

Related Security Bulletins