UBUNTU-CVE-2021-37147
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-37147
Summary:
Details: Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0.
References: https://ubuntu.com/security/CVE-2021-37147, https://www.openwall.com/lists/oss-security/2021/11/02/11, https://github.com/apache/trafficserver/commit/64f25678bfbbd1433cce703e3c43bcc49a53de56, https://github.com/apache/trafficserver/commit/5cad961c87cb07fbb8fa6890685d9878a169378d, https://github.com/apache/trafficserver/pull/8460, https://www.cve.org/CVERecord?id=CVE-2021-37147
Affected packages
Package
Name: trafficserver
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
