Varnish Enterprise
cpe:2.3:a:varnish-software:varnish_enterprise:*:*:*:*:*:*:*
- >= 6.0.9r5, <= 6.0.16r11
A denial-of-service vulnerability has been identified in Varnish Enterprise versions 6.0.9r5 prior to 6.0.16r11. The issue arises in shared VCL deployments, where the 'headerplus.write_req0()' function from 'vmod_headerplus' can cause a 'workspace overflow'. This function updates the 'req0' with header fields from 'req', which is normally read-only. If too many headers are added, it can lead to a workspace overflow, triggering a daemon panic and crashing the Varnish server. This vulnerability can be exploited by malicious clients to cause a denial-of-service condition.
Exploitation of this vulnerability leads to a daemon panic, causing the Varnish Enterprise server to crash.
Users are advised to upgrade Varnish Enterprise to version 6.0.16r12 or later and ensure that Varnish is restarted.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.