LibHTP is a security-aware parser for the HTTP protocol. Crafted traffic can cause excessive processing time of HTTP headers, leading to denial of service. This issue is addressed in 0.5.46.
References
Configurations
History
07 Feb 2025, 17:35
Type | Values Removed | Values Added |
---|---|---|
First Time |
Fedoraproject
Oisf libhtp Fedoraproject fedora Oisf |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
References | () https://github.com/OISF/libhtp/commit/20ac301d801cdf01b3f021cca08a22a87f477c4a - Patch | |
References | () https://redmine.openinfosecfoundation.org/issues/6444 - Exploit | |
References | () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZXJIT7R53ZXROO3I256RFUWTIW4ECK6P/ - Mailing List | |
References | () https://github.com/OISF/libhtp/security/advisories/GHSA-f9wf-rrjj-qx8m - Vendor Advisory | |
References | () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GOCOBFUTIFHOP2PZOH4ENRFXRBHIRKK4/ - Mailing List | |
CPE | cpe:2.3:a:oisf:libhtp:*:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* |
|
CWE | CWE-770 |
07 Mar 2024, 03:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
26 Feb 2024, 16:32
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-02-26 16:27
Updated : 2025-02-07 17:35
NVD link : CVE-2024-23837
Mitre link : CVE-2024-23837
JSON object : View
Products Affected
oisf
- libhtp
fedoraproject
- fedora
CWE
CWE-770
Allocation of Resources Without Limits or Throttling