// For flags

CVE-2019-15892

varnish: denial of service handling certain crafted HTTP/1 requests

Severity Score

7.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure allows a remote attacker to trigger an assert by sending crafted HTTP/1 requests. The assert will cause an automatic restart with a clean cache, which makes it a Denial of Service attack.

Se detecto un problema en Varnish Cache en versiones anteriores a la 6.0.4 LTS y 6.1.x y 6.2.x en versiones anteriores a la 6.2.1. Un error de análisis HTTP/1 permite a un atacante remoto desencadenar una aserción mediante el envío de solicitudes HTTP/1 diseñadas. La aserción provocará un reinicio automático con una memoria caché limpia, lo que la convierte en un ataque de Denegación de Servicio.

A flaw was found in the way Varnish parsed certain HTTP/1 requests. A remote attacker could use this flaw to crash Varnish by sending specially crafted multiple HTTP/1 requests processed on the same HTTP/1 keep-alive connection. This causes Varnish to restart with a clean cache, causing a denial of service.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-09-03 CVE Reserved
  • 2019-09-03 CVE Published
  • 2024-08-05 CVE Updated
  • 2024-08-27 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-20: Improper Input Validation
  • CWE-617: Reachable Assertion
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Varnish-software
Search vendor "Varnish-software"
Varnish Cache
Search vendor "Varnish-software" for product "Varnish Cache"
>= 6.0.0 < 6.0.4
Search vendor "Varnish-software" for product "Varnish Cache" and version " >= 6.0.0 < 6.0.4"
lts
Affected
Varnish Cache Project
Search vendor "Varnish Cache Project"
Varnish Cache
Search vendor "Varnish Cache Project" for product "Varnish Cache"
>= 6.1.0 <= 6.1.1
Search vendor "Varnish Cache Project" for product "Varnish Cache" and version " >= 6.1.0 <= 6.1.1"
-
Affected
Varnish Cache Project
Search vendor "Varnish Cache Project"
Varnish Cache
Search vendor "Varnish Cache Project" for product "Varnish Cache"
>= 6.2.0 < 6.2.1
Search vendor "Varnish Cache Project" for product "Varnish Cache" and version " >= 6.2.0 < 6.2.1"
-
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
10.0
Search vendor "Debian" for product "Debian Linux" and version "10.0"
-
Affected