Varnish before 3.0.5 allows remote attackers to cause a denial of service (child-process crash and temporary caching outage) via a GET request with trailing whitespace characters and no URI.
{
"binaries": [
{
"binary_version": "3.0.5-2",
"binary_name": "libvarnishapi-dev"
},
{
"binary_version": "3.0.5-2",
"binary_name": "libvarnishapi1"
},
{
"binary_version": "3.0.5-2",
"binary_name": "varnish"
},
{
"binary_version": "3.0.5-2",
"binary_name": "varnish-dbg"
},
{
"binary_version": "3.0.5-2",
"binary_name": "varnish-doc"
}
],
"availability": "No subscription required"
}