USN-5474-1 fixed vulnerabilities in Varnish Cache. Unfortunately the fix for CVE-2020-11653 was incomplete. This update fixes the problem.
Original advisory details:
It was discovered that Varnish Cache could have an assertion failure when a TLS termination proxy uses PROXY version 2. A remote attacker could possibly use this issue to restart the daemon and cause a performance loss. (CVE-2020-11653)
{ "availability": "No subscription required", "binaries": [ { "binary_version": "6.2.1-2ubuntu0.2", "binary_name": "libvarnishapi-dev" }, { "binary_version": "6.2.1-2ubuntu0.2", "binary_name": "libvarnishapi2" }, { "binary_version": "6.2.1-2ubuntu0.2", "binary_name": "libvarnishapi2-dbgsym" }, { "binary_version": "6.2.1-2ubuntu0.2", "binary_name": "varnish" }, { "binary_version": "6.2.1-2ubuntu0.2", "binary_name": "varnish-dbgsym" }, { "binary_version": "6.2.1-2ubuntu0.2", "binary_name": "varnish-doc" } ] }