[Bug 1231746] New: VUL-0: CVE-2024-45797: libhtp: unbounded header handling leads to denial of service
https://bugzilla.suse.com/show_bug.cgi?id=1231746 Bug ID: 1231746 Summary: VUL-0: CVE-2024-45797: libhtp: unbounded header handling leads to denial of service Classification: openSUSE Product: openSUSE Distribution Version: Leap 15.6 Hardware: Other URL: https://smash.suse.de/issue/424387/ OS: Other Status: NEW Severity: Major Priority: P5 - None Component: Security Assignee: nix@opensuse.org Reporter: smash_bz@suse.de QA Contact: security-team@suse.de CC: abergmann@suse.com Target Milestone: --- Found By: Security Response Team Blocker: --- LibHTP is a security-aware parser for the HTTP protocol and the related bits and pieces. Prior to version 0.5.49, unbounded processing of HTTP request and response headers can lead to excessive CPU time and memory utilization, possibly leading to extreme slowdowns. This issue is addressed in 0.5.49. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-45797 https://www.cve.org/CVERecord?id=CVE-2024-45797 https://github.com/OISF/libhtp/security/advisories/GHSA-rqqp-24ch-248f https://redmine.openinfosecfoundation.org/issues/7191 -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1231746 SMASH SMASH <smash_bz@suse.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Whiteboard| |CVSSv3.1:SUSE:CVE-2024-4579 | |7:7.5:(AV:N/AC:L/PR:N/UI:N/ | |S:U/C:N/I:N/A:H) | |CVSSv4:SUSE:CVE-2024-45797: | |8.7:(AV:N/AC:L/AT:N/PR:N/UI | |:N/VC:N/VI:N/VA:H/SC:N/SI:N | |/SA:N) -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1231746 SMASH SMASH <smash_bz@suse.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Priority|P5 - None |P3 - Medium -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com