header-logo
Suggest Exploit
vendor:
Varnish Cache
by:
SecurityFocus
7,5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: Varnish Cache
Affected Version From: 2.1.5
Affected Version To: Other versions may also be affected.
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2013

Varnish Cache Denial of Service Vulnerabilities

Varnish Cache is prone to multiple denial-of-service vulnerabilities. An attacker can exploit these issues to crash the application, effectively denying service to legitimate users. Varnish Cache 2.1.5 is vulnerable; other versions may also be affected.

Mitigation:

Upgrade to the latest version of Varnish Cache.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/58314/info

Varnish Cache is prone to multiple denial-of-service vulnerabilities.

An attacker can exploit these issues to crash the application, effectively denying service to legitimate users.

Varnish Cache 2.1.5 is vulnerable; other versions may also be affected. 

The following example data is available:

HTTP/1.1 200 OK
Content-Type: text/xml; charset=utf-8
Content-Length: 99999999999999999

HTTP/1.1 200 OK
Content-Length: 2147483647