|
|
Log in / Subscribe / Register

Ubuntu alert USN-7372-1 (varnish)

From:  Bruce Cable <bruce.cable@canonical.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-7372-1] Varnish vulnerability
Date:  Wed, 26 Mar 2025 15:22:43 +1100
Message-ID:  <5a26f25e-15b1-4ea3-b193-82ed18a01746@canonical.com>

========================================================================== Ubuntu Security Notice USN-7372-1 March 26, 2025 varnish vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Varnish could allow unintended access to network services. Software Description: - varnish: state of the art, high-performance web accelerator Details: Martin van Kervel Smedshammer discovered that Varnish did not properly sanitize certain HTTP headers. A remote attacker could possibly use this issue to perform a cross-site request forgery (CSRF) attack. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS   libvarnishapi2                  6.6.1-1ubuntu0.2+esm1                                   Available with Ubuntu Pro   varnish                         6.6.1-1ubuntu0.2+esm1                                   Available with Ubuntu Pro Ubuntu 20.04 LTS   libvarnishapi2                  6.2.1-2ubuntu0.2+esm1                                   Available with Ubuntu Pro   varnish                         6.2.1-2ubuntu0.2+esm1                                   Available with Ubuntu Pro Ubuntu 18.04 LTS   libvarnishapi1                  5.2.1-1ubuntu0.1+esm1                                   Available with Ubuntu Pro   varnish                         5.2.1-1ubuntu0.1+esm1                                   Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References:   https://ubuntu.com/security/notices/USN-7372-1   CVE-2022-45060


Attachment: OpenPGP_signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- wsD5BAABCAAjFiEEkd98mdFcnQdP7vQkuGrtzot7pOcFAmfjgRMFAwAAAAAACgkQuGrtzot7pOfY lAwAiCTMAuVTh7Uh73hEy2304nsz2o3LO7eCg0YlSbVbuIe/UpR1fiKc9AtzM++WAc1tQkpvqo08 lum9LEenZeKxqAGNIQ3d38MRJiArti6j7E2XnsjlGTPAu6S7v1v65/TAOig2B5GrwO+X36xnfmbh W8Wp4NNwgg+bXAvZblEVM5YJTZbK9/Uy1yp+B9hzvgvMWVXwuLcXaRnU8f8ccl1FcRoIZBa+CLV8 YtLl0qPl2hrEJnAS3aBL97F6wlHrugZSAl+Luq1vGvZz+EXZ06+5Qyy8M3FDgr6PTeWPkp6LcIFl tx351y+N4+wCUhhfvBL9rtjxVHFkbONJQiSnhJ+6vJjbwFbYcOXo8St5jE7RQM59aKeUYaJZEorg RAiRZVnLHSclZX9NtkNZrBQtTFGtcJ4UJl8nz/KM/avZFxkChRBfVW3bYb1Tj2+iUeBkqyu/2qq/ i48mtr39Ce97KPungdqyhHucy1gMmETyz/aKwiWc8RCUP76o2g3F+6IuDRgZ =Z3la -----END PGP SIGNATURE-----


Attachment: None (type=text/plain)


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds