Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-8852

Опубликовано: 12 мар. 2015
Источник: redhat
CVSS2: 5.8

Описание

Varnish 3.x before 3.0.7, when used in certain stacked installations, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a header line terminated by a \r (carriage return) character in conjunction with multiple Content-Length headers in an HTTP request.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Software Collectionsrh-varnish4-varnishNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-113

5.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 10 лет назад

Varnish 3.x before 3.0.7, when used in certain stacked installations, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a header line terminated by a \r (carriage return) character in conjunction with multiple Content-Length headers in an HTTP request.

CVSS3: 7.5
nvd
больше 10 лет назад

Varnish 3.x before 3.0.7, when used in certain stacked installations, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a header line terminated by a \r (carriage return) character in conjunction with multiple Content-Length headers in an HTTP request.

CVSS3: 7.5
debian
больше 10 лет назад

Varnish 3.x before 3.0.7, when used in certain stacked installations, ...

CVSS3: 7.5
github
больше 4 лет назад

Varnish 3.x before 3.0.7, when used in certain stacked installations, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a header line terminated by a \r (carriage return) character in conjunction with multiple Content-Length headers in an HTTP request.

5.8 Medium

CVSS2