MGASA-2020-0154

Source
https://advisories.mageia.org/MGASA-2020-0154.html
Import Source
https://advisories.mageia.org/MGASA-2020-0154.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2020-0154
Published
2020-04-02T22:48:49Z
Modified
2026-04-16T04:25:57.753342Z
Summary
Updated varnish packages fix security vulnerability
Details

Updated varnish packages fix security vulnerability:

An assert can be triggered in Varnish Cache when using Varnish with a TLS termination proxy, and the proxy and Varnish use the PROXY version 2. The assert will cause Varnish to restart, and the cache will be empty after the restart (VSV00005).

References
Credits

Affected packages

Mageia:7 / varnish

Package

Name
varnish
Purl
pkg:rpm/mageia/varnish?arch=source&distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.3.2-1.mga7

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2020-0154.json"