UBUNTU-CVE-2020-11653
Dashboard / Vulnerabilities / UBUNTU-CVE-2020-11653
UBUNTU-CVE-2020-11653
Summary:
Details: An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when communication with a TLS termination proxy uses PROXY version 2. There can be an assertion failure and daemon restart, which causes a performance loss.
References: https://ubuntu.com/security/CVE-2020-11653, https://varnish-cache.org/security/VSV00005.html#vsv00005, https://github.com/varnishcache/varnish-cache/commit/2d8fc1a784a1e26d78c30174923a2b14ee2ebf62, https://ubuntu.com/security/notices/USN-5474-1, https://www.cve.org/CVERecord?id=CVE-2020-11653, https://ubuntu.com/security/notices/USN-5474-2
Affected packages
Package
Name: varnish
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=focal
Affected ranges
Type: ECOSYSTEM
Events:
