Ubuntu Security Notice 5474-2 - USN-5474-1 fixed vulnerabilities in Varnish Cache. Unfortunately the fix for CVE-2020-11653 was incomplete. This update fixes the problem. It was discovered that Varnish Cache could have an assertion failure when a TLS termination proxy uses PROXY version 2. A remote attacker could possibly use this issue to restart the daemon and cause a performance loss.
9f42bd8d47eeef57534724a225acf2e6270a8437cec9bc39c2b61610b5595336
Ubuntu Security Notice 5474-1 - It was dicovered that Varnish Cache did not clear a pointer between the handling of one client request and the next request within the same connection. A remote attacker could possibly use this issue to obtain sensitive information. It was discovered that Varnish Cache could have an assertion failure when a TLS termination proxy uses PROXY version 2. A remote attacker could possibly use this issue to restart the daemon and cause a performance loss.
5974b74ed2f5b285513dbf02f7b51df56bc6247a280243707c50784d224f5c90
Red Hat Security Advisory 2020-4756-01 - Varnish Cache is a high-performance HTTP accelerator. It stores web pages in memory so web servers don't have to create the same web page over and over again, giving the website a significant speed up. Issues addressed include denial of service and information leakage vulnerabilities.
fdc73995495cf1695de4dbbeabae1e8e035727f03673f92adcac9db34e567f19