This is a pretty special corner case, way outside what we promise
Varnish will do, so I have decided it does not qualify for a
security-advisory, however, the announce list is my only way to
communicate with the very few people this issue applies to:

    You run varnishd as root
    You use privilege separation
    You accept VCL programs from untrusted sources
    You allow the VCL programs to contain inline-C or unverified VMODs. 

Then please check the 2012-04-28 entry on:

