Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2024-1691

Опубликовано: 09 апр. 2024
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2024-1691: varnish security update (IMPORTANT)

[6.6.2-4.1]

  • Resolves: RHEL-30387 - varnish: HTTP/2 Broken Window Attack may result in denial of service (CVE-2024-30156)

[6.6.2-4]

  • Add parameters h2_rst_allowance and h2_rst_allowance_period to mitigate CVE-2023-44487
  • Resolves: RHEL-12817

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

varnish

6.6.2-4.el9_3.1

varnish-devel

6.6.2-4.el9_3.1

varnish-docs

6.6.2-4.el9_3.1

Oracle Linux x86_64

varnish

6.6.2-4.el9_3.1

varnish-devel

6.6.2-4.el9_3.1

varnish-docs

6.6.2-4.el9_3.1

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 года назад

Varnish Cache before 7.3.2 and 7.4.x before 7.4.3 (and before 6.0.13 LTS), and Varnish Enterprise 6 before 6.0.12r6, allows credits exhaustion for an HTTP/2 connection control flow window, aka a Broke Window Attack.

CVSS3: 7.5
redhat
около 1 года назад

Varnish Cache before 7.3.2 and 7.4.x before 7.4.3 (and before 6.0.13 LTS), and Varnish Enterprise 6 before 6.0.12r6, allows credits exhaustion for an HTTP/2 connection control flow window, aka a Broke Window Attack.

CVSS3: 7.5
nvd
около 1 года назад

Varnish Cache before 7.3.2 and 7.4.x before 7.4.3 (and before 6.0.13 LTS), and Varnish Enterprise 6 before 6.0.12r6, allows credits exhaustion for an HTTP/2 connection control flow window, aka a Broke Window Attack.

CVSS3: 7.5
debian
около 1 года назад

Varnish Cache before 7.3.2 and 7.4.x before 7.4.3 (and before 6.0.13 L ...

rocky
около 1 года назад

Important: varnish security update