MGASA-2022-0079
Dashboard / Vulnerabilities / MGASA-2022-0079
Summary: Updated varnish packages fix security vulnerability
Details: In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, request smuggling can occur for HTTP/1 connections. (CVE-2022-23959)
References: https://advisories.mageia.org/MGASA-2022-0079.html, https://bugs.mageia.org/show_bug.cgi?id=30048, https://www.debian.org/lts/security/2022/dla-2920, https://docs.varnish-software.com/security/VSV00008/, https://lists.fedoraproject.org/archives/list/[email protected]/thread/UMMDMQWNAE3BTSZUHXQHVAMZC5TLHLYT/
Affected packages
Package
Name: varnish
Purl: pkg:rpm/mageia/varnish?arch=source&distro=mageia-8
Affected ranges
Type: ECOSYSTEM
Events:
