Out-of-Bounds Memory Access in libvmod-digest for Varnish Enterprise
CVE-2023-41104
6.5MEDIUM
What is CVE-2023-41104?
The vulnerability in libvmod-digest allows for an out-of-bounds memory access during base64 decoding. This issue, present in versions prior to 1.0.3, can lead to both authentication bypass and information disclosure. The potential impact of the vulnerability is influenced by the specific configuration of Varnish Configuration Language (VCL) in use, making certain configurations more susceptible to exploitation. It is advisable for users of Varnish Enterprise 6.0.x to review their VCL settings and upgrade to the patched version to mitigate this risk.
