UBUNTU-CVE-2021-32565
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-32565
Summary:
Details: Invalid values in the Content-Length header sent to Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.
References: https://ubuntu.com/security/CVE-2021-32565, https://lists.apache.org/thread.html/ra1a41ff92a70d25bf576d7da2590575e8ff430393a3f4a0c34de4277%40%3Cannounce.trafficserver.apache.org%3E, https://github.com/apache/trafficserver/pull/7945, https://github.com/apache/trafficserver/commit/668d0f8668fec1cd350b0ceba3f7f8e4020ae3ca, https://github.com/apache/trafficserver/commit/b82a3d192f995fb9d78e1c44d51d9acca4783277, https://www.cve.org/CVERecord?id=CVE-2021-32565
Affected packages
Package
Name: trafficserver
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
