Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-8337

Опубликовано: 02 июн. 2025
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2025-8337: varnish security update (IMPORTANT)

[6.6.2-6.1]

  • Resolves: RHEL-89700 - varnish: request smuggling attacks (CVE-2025-47905)

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

varnish

6.6.2-6.el9_6.1

varnish-devel

6.6.2-6.el9_6.1

varnish-docs

6.6.2-6.el9_6.1

Oracle Linux x86_64

varnish

6.6.2-6.el9_6.1

varnish-devel

6.6.2-6.el9_6.1

varnish-docs

6.6.2-6.el9_6.1

Связанные CVE

Связанные уязвимости

CVSS3: 5.4
ubuntu
около 1 месяца назад

Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.

CVSS3: 8.1
redhat
около 1 месяца назад

Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.

CVSS3: 5.4
nvd
около 1 месяца назад

Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.

CVSS3: 5.4
debian
около 1 месяца назад

Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterpris ...

CVSS3: 5.4
github
около 1 месяца назад

Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.