From owner-freebsd-ports-bugs@FreeBSD.ORG Sun Feb 15 06:30:02 2009 Return-Path: Delivered-To: freebsd-ports-bugs@hub.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 24D5D106564A for ; Sun, 15 Feb 2009 06:30:02 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [IPv6:2001:4f8:fff6::28]) by mx1.freebsd.org (Postfix) with ESMTP id 00B518FC15 for ; Sun, 15 Feb 2009 06:30:02 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1]) by freefall.freebsd.org (8.14.3/8.14.3) with ESMTP id n1F6U1Jb083899 for ; Sun, 15 Feb 2009 06:30:01 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.14.3/8.14.3/Submit) id n1F6U1s3083897; Sun, 15 Feb 2009 06:30:01 GMT (envelope-from gnats) Resent-Date: Sun, 15 Feb 2009 06:30:01 GMT Resent-Message-Id: <200902150630.n1F6U1s3083897@freefall.freebsd.org> Resent-From: FreeBSD-gnats-submit@FreeBSD.org (GNATS Filer) Resent-To: freebsd-ports-bugs@FreeBSD.org Resent-Reply-To: FreeBSD-gnats-submit@FreeBSD.org, Mark Foster Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id CFCBB1065672 for ; Sun, 15 Feb 2009 06:21:58 +0000 (UTC) (envelope-from nobody@FreeBSD.org) Received: from www.freebsd.org (www.freebsd.org [IPv6:2001:4f8:fff6::21]) by mx1.freebsd.org (Postfix) with ESMTP id BE5FE8FC13 for ; Sun, 15 Feb 2009 06:21:58 +0000 (UTC) (envelope-from nobody@FreeBSD.org) Received: from www.freebsd.org (localhost [127.0.0.1]) by www.freebsd.org (8.14.3/8.14.3) with ESMTP id n1F6LwGx051452 for ; Sun, 15 Feb 2009 06:21:58 GMT (envelope-from nobody@www.freebsd.org) Received: (from nobody@localhost) by www.freebsd.org (8.14.3/8.14.3/Submit) id n1F6LwUm051450; Sun, 15 Feb 2009 06:21:58 GMT (envelope-from nobody) Message-Id: <200902150621.n1F6LwUm051450@www.freebsd.org> Date: Sun, 15 Feb 2009 06:21:58 GMT From: Mark Foster To: freebsd-gnats-submit@FreeBSD.org X-Send-Pr-Version: www-3.1 Cc: Subject: ports/131690: vuxml submission for www/varnish X-BeenThere: freebsd-ports-bugs@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Ports bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 15 Feb 2009 06:30:02 -0000 >Number: 131690 >Category: ports >Synopsis: vuxml submission for www/varnish >Confidential: no >Severity: non-critical >Priority: low >Responsible: freebsd-ports-bugs >State: open >Quarter: >Keywords: >Date-Required: >Class: update >Submitter-Id: current-users >Arrival-Date: Sun Feb 15 06:30:01 UTC 2009 >Closed-Date: >Last-Modified: >Originator: Mark Foster >Release: 7.1 RELEASE >Organization: Credentia >Environment: >Description: >How-To-Repeat: >Fix: varnish -- Varnish HTTP Request Parsing Denial of Service varnish 2.0.1

SecurityFocus reports:

Varnish is prone to a remote denial-of-service vulnerability because the application fails to handle certain HTTP requests. Successfully exploiting this issue allows remote attackers to crash the affected application denying further service to legitimate users.

33712 http://www.securityfocus.com/bid/33712 2008-10-17 2009-02-14
>Release-Note: >Audit-Trail: >Unformatted: