Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-38150
HistoryAug 11, 2022 - 12:00 a.m.

CVE-2022-38150

2022-08-1100:00:00
ubuntu.com
ubuntu.com
27
varnish cache
http/1
backend response
forged
cause
assert
restart
fixed
version 7.0.3
version 7.1.1

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

51.7%

In Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause
the Varnish Server to assert and automatically restart through forged
HTTP/1 backend responses. An attack uses a crafted reason phrase of the
backend response status line. This is fixed in 7.0.3 and 7.1.1.

Notes

Author Note
mdeslaur only affects 7.0 and higher
OSVersionArchitecturePackageVersionFilename
ubuntu16.04noarchvarnish< anyUNKNOWN

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

51.7%