Varnish before 3.0.5 allows remote attackers to cause a denial of service (child-process crash and temporary caching outage) via a GET request with trailing whitespace characters and no URI.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "libvarnishapi-dev",
"binary_version": "3.0.5-2"
},
{
"binary_name": "libvarnishapi1",
"binary_version": "3.0.5-2"
},
{
"binary_name": "varnish",
"binary_version": "3.0.5-2"
},
{
"binary_name": "varnish-dbg",
"binary_version": "3.0.5-2"
},
{
"binary_name": "varnish-doc",
"binary_version": "3.0.5-2"
}
]
}