Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2024:1690

Опубликовано: 06 мая 2024
Источник: rocky
Оценка: Important

Описание

Important: varnish security update

Varnish Cache is a high-performance HTTP accelerator. It stores web pages in memory so web servers don't have to create the same web page over and over again, giving the website a significant speed up.

Security Fix(es):

  • varnish: HTTP/2 Broken Window Attack may result in denial of service (CVE-2024-30156)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
varnishx86_641.module+el8.9.0+1777+0acf9965varnish-6.0.13-1.module+el8.9.0+1777+0acf9965.x86_64.rpm
varnish-develx86_641.module+el8.9.0+1777+0acf9965varnish-devel-6.0.13-1.module+el8.9.0+1777+0acf9965.x86_64.rpm
varnish-docsx86_641.module+el8.9.0+1777+0acf9965varnish-docs-6.0.13-1.module+el8.9.0+1777+0acf9965.x86_64.rpm
varnish-modulesx86_646.module+el8.5.0+677+2a78a869varnish-modules-0.15.0-6.module+el8.5.0+677+2a78a869.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 1 года назад

Varnish Cache before 7.3.2 and 7.4.x before 7.4.3 (and before 6.0.13 LTS), and Varnish Enterprise 6 before 6.0.12r6, allows credits exhaustion for an HTTP/2 connection control flow window, aka a Broke Window Attack.

CVSS3: 7.5
redhat
больше 1 года назад

Varnish Cache before 7.3.2 and 7.4.x before 7.4.3 (and before 6.0.13 LTS), and Varnish Enterprise 6 before 6.0.12r6, allows credits exhaustion for an HTTP/2 connection control flow window, aka a Broke Window Attack.

CVSS3: 7.5
nvd
больше 1 года назад

Varnish Cache before 7.3.2 and 7.4.x before 7.4.3 (and before 6.0.13 LTS), and Varnish Enterprise 6 before 6.0.12r6, allows credits exhaustion for an HTTP/2 connection control flow window, aka a Broke Window Attack.

CVSS3: 7.5
debian
больше 1 года назад

Varnish Cache before 7.3.2 and 7.4.x before 7.4.3 (and before 6.0.13 L ...

rocky
больше 1 года назад

Important: varnish security update