Description
Varnish 3.x before 3.0.7, when used in certain stacked installations, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a header line terminated by a \r (carriage return) character in conjunction with multiple Content-Length headers in an HTTP request.
References (8)
Core 8
Core References
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2016/dsa-3553
Vendor Advisory mailing-list
x_refsource_mlist
https://www.varnish-cache.org/lists/pipermail/varnish-announce/2015-March/000701.html
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2016/04/18/7
Third Party Advisory vendor-advisory
x_refsource_gentoo
https://security.gentoo.org/glsa/201607-10
Patch x_refsource_confirm
https://github.com/varnish/Varnish-Cache/commit/29870c8fe95e4e8a672f6f28c5fbe692bea09e9c
Patch x_refsource_confirm
https://github.com/varnish/Varnish-Cache/commit/85e8468bec9416bd7e16b0d80cb820ecd2b330c3
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2016/04/16/1
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2016-05/msg00064.html
Scores
CVSS v3
7.5
EPSS
0.0343
EPSS Percentile
87.4%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Details
Status
published
Products (8)
debian/debian_linux
7.0
varnish_cache_project/varnish_cache
3.0.0 beta1 (2 CPE variants)
varnish_cache_project/varnish_cache
3.0.1
varnish_cache_project/varnish_cache
3.0.2
varnish_cache_project/varnish_cache
3.0.3
varnish_cache_project/varnish_cache
3.0.4
varnish_cache_project/varnish_cache
3.0.5
varnish_cache_project/varnish_cache
3.0.6
Published
Apr 25, 2016
Tracked Since
Feb 18, 2026