Sploitus

CVE-2009-4488

2 known exploits for CVE-2009-4488

Varnish 2.0.6 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator. NOTE: the vendor disputes the significance of this report, stating that "This is not a security problem in Varnish or any other piece of software which writes a logfile. The real problem is the mistaken belief that you can cat(1) a random logfile to your terminal safely.

Affected products
Debian, Varnish
Varnish.projects.linpro Varnish
= 2.0.6
CVSS 3.1
9.8 CRITICAL
EPSS
12.8% (96th percentile)
Weakness
CWE-20, CWE-1284
NVD status
Modified
Published
2010-01-13
CVE-2009-4488 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2009-4488

Proof-of-concept code and exploit modules indexed by Sploitus