Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-8550

Опубликовано: 26 июн. 2025
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2025-8550: varnish security update (IMPORTANT)

[7.6.1-2.el10_0.1]

  • Resolves: RHEL-89691 - varnish: request smuggling attacks (CVE-2025-47905)

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

varnish

7.6.1-2.el10_0.1

varnish-docs

7.6.1-2.el10_0.1

varnish-devel

7.6.1-2.el10_0.1

Oracle Linux x86_64

varnish

7.6.1-2.el10_0.1

varnish-docs

7.6.1-2.el10_0.1

varnish-devel

7.6.1-2.el10_0.1

Связанные CVE

Связанные уязвимости

CVSS3: 5.4
ubuntu
3 месяца назад

Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.

CVSS3: 8.1
redhat
3 месяца назад

Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.

CVSS3: 5.4
nvd
3 месяца назад

Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.

CVSS3: 5.4
debian
3 месяца назад

Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterpris ...

CVSS3: 5.4
github
3 месяца назад

Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.