Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2025:8336

Опубликовано: 29 июл. 2025
Источник: rocky
Оценка: Important

Описание

Important: varnish:6 security update

Varnish Cache is a high-performance HTTP accelerator. It stores web pages in memory so web servers don't have to create the same web page over and over again, giving the website a significant speed up.

Security Fix(es):

  • varnish: request smuggling attacks (CVE-2025-47905)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
varnishx86_641.module+el8.10.0+1982+334a201b.1varnish-6.0.13-1.module+el8.10.0+1982+334a201b.1.x86_64.rpm
varnishx86_641.module+el8.9.0+1777+0acf9965varnish-6.0.13-1.module+el8.9.0+1777+0acf9965.x86_64.rpm
varnish-develx86_641.module+el8.10.0+1982+334a201b.1varnish-devel-6.0.13-1.module+el8.10.0+1982+334a201b.1.x86_64.rpm
varnish-develx86_641.module+el8.9.0+1777+0acf9965varnish-devel-6.0.13-1.module+el8.9.0+1777+0acf9965.x86_64.rpm
varnish-docsx86_641.module+el8.10.0+1982+334a201b.1varnish-docs-6.0.13-1.module+el8.10.0+1982+334a201b.1.x86_64.rpm
varnish-docsx86_641.module+el8.9.0+1777+0acf9965varnish-docs-6.0.13-1.module+el8.9.0+1777+0acf9965.x86_64.rpm
varnish-modulesx86_646.module+el8.5.0+677+2a78a869varnish-modules-0.15.0-6.module+el8.5.0+677+2a78a869.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 5.4
ubuntu
7 месяцев назад

Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.

CVSS3: 8.1
redhat
7 месяцев назад

Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.

CVSS3: 5.4
nvd
7 месяцев назад

Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.

CVSS3: 5.4
debian
7 месяцев назад

Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterpris ...

rocky
3 месяца назад

Important: varnish security update