CVE-2013-4484
Varnish before 3.0.5 allows remote attackers to cause a denial of service (child-process crash and temporary caching outage) via a GET request with trailing whitespace characters and no URI.
- Affected products
- Varnish
- Varnish-cache Varnish
- = 2.0.0
- Varnish Cache Project Varnish Cache
- ≤ 3.0.4, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.1.4, 2.1.5, 3.0.0, 3.0.1, 3.0.2, 3.0.3
- Fix
- Available
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 3.0% (86th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2013-11-01
CVE-2013-4484 at NVD
2 known exploits for CVE-2013-4484
Proof-of-concept code and exploit modules indexed by Sploitus