Vulnerability Name:

CVE-2019-15892 (CCN-166529)

Assigned:2019-09-03
Published:2019-09-03
Updated:2022-08-02
Summary:An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure allows a remote attacker to trigger an assert by sending crafted HTTP/1 requests. The assert will cause an automatic restart with a clean cache, which makes it a Denial of Service attack.
CVSS v3 Severity:7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
7.5 High (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-617
CWE-20
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2019-15892

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2019:2184

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2019:2221

Source: XF
Type: UNKNOWN
varnishcache-cve201915892-dos(166529)

Source: FEDORA
Type: UNKNOWN
FEDORA-2019-a0a0cdef92

Source: FEDORA
Type: UNKNOWN
FEDORA-2019-feec5e0afd

Source: FEDORA
Type: UNKNOWN
FEDORA-2019-8a85a90af6

Source: BUGTRAQ
Type: Mailing List, Third Party Advisory
20190904 [SECURITY] [DSA 4514-1] varnish security update

Source: CCN
Type: BugTraq Mailing List, Wed, 4 Sep 2019 07:08:37 +0000
[SECURITY] [DSA 4514-1] varnish security update

Source: CCN
Type: Varnish Cache Web site
VSV00003 DoS attack vector

Source: MISC
Type: Vendor Advisory
https://varnish-cache.org/security/VSV00003.html

Source: DEBIAN
Type: Third Party Advisory
DSA-4514

Vulnerable Configuration:Configuration 1:
  • cpe:/a:varnish_cache_project:varnish_cache:*:*:*:*:*:*:*:* (Version >= 6.2.0 and < 6.2.1)
  • OR cpe:/a:varnish_cache_project:varnish_cache:*:*:*:*:*:*:*:* (Version >= 6.1.0 and <= 6.1.1)
  • OR cpe:/a:varnish-software:varnish_cache:*:*:*:*:lts:*:*:* (Version >= 6.0.0 and < 6.0.4)

  • Configuration 2:
  • cpe:/o:debian:debian_linux:10.0:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/a:redhat:enterprise_linux:8:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/a:redhat:enterprise_linux:8::appstream:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:93471
    P
    (Important)
    2022-07-12
    oval:org.opensuse.security:def:201915892
    V
    CVE-2019-15892
    2022-06-30
    oval:org.opensuse.security:def:112899
    P
    libvarnishapi2-6.6.1-1.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:74384
    P
    Security update for flatpak (Important)
    2021-10-20
    oval:org.opensuse.security:def:106358
    P
    libvarnishapi2-6.6.1-1.2 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:63495
    P
    libstaroffice-0_0-0-0.0.7-7.3.2 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63131
    P
    rmt-server-pubcloud-2.6.8-1.2 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63269
    P
    libapr-util1-dbd-mysql-1.6.1-10.21 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62449
    P
    libjpeg8-32bit-8.1.2-3.21 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62650
    P
    libQt5OpenGLExtensions-devel-static-5.12.7-2.25 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62450
    P
    libkpathsea6-6.2.3-9.35 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62929
    P
    zlib-devel-32bit-1.2.11-3.6.4 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62473
    P
    libtasn1-6-32bit-4.13-2.15 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63956
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:64318
    P
    libbluetooth3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64062
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:74258
    P
    Security update for enigmail (Important)
    2020-12-01
    oval:org.opensuse.security:def:64164
    P
    Security update for spice (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63822
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:64206
    P
    alsa on GA media (Moderate)
    2020-12-01
    oval:com.redhat.rhsa:def:20204756
    P
    RHSA-2020:4756: varnish:6 security, bug fix, and enhancement update (Moderate)
    2020-11-04
    oval:org.opensuse.security:def:100184
    P
    Security update for varnish (Moderate)
    2019-09-30
    oval:org.opensuse.security:def:110008
    P
    Security update for varnish (Moderate)
    2019-09-25
    oval:com.ubuntu.disco:def:2019158920000000
    V
    CVE-2019-15892 on Ubuntu 19.04 (disco) - medium.
    2019-09-03
    oval:com.ubuntu.bionic:def:2019158920000000
    V
    CVE-2019-15892 on Ubuntu 18.04 LTS (bionic) - untriaged.
    2019-09-03
    oval:com.ubuntu.xenial:def:2019158920000000
    V
    CVE-2019-15892 on Ubuntu 16.04 LTS (xenial) - untriaged.
    2019-09-03
    BACK
    varnish_cache_project varnish cache *
    varnish_cache_project varnish cache *
    varnish-software varnish cache *
    debian debian linux 10.0