UBUNTU-CVE-2024-23837
Dashboard / Vulnerabilities / UBUNTU-CVE-2024-23837
UBUNTU-CVE-2024-23837
Summary:
Details: LibHTP is a security-aware parser for the HTTP protocol. Crafted traffic can cause excessive processing time of HTTP headers, leading to denial of service. This issue is addressed in 0.5.46.
References: https://ubuntu.com/security/CVE-2024-23837, https://github.com/OISF/libhtp/security/advisories/GHSA-f9wf-rrjj-qx8m, https://github.com/OISF/libhtp/commit/20ac301d801cdf01b3f021cca08a22a87f477c4a, https://redmine.openinfosecfoundation.org/issues/6444, https://github.com/OISF/libhtp/commit/20ac301d801cdf01b3f021cca08a22a87f477c4a, https://www.cve.org/CVERecord?id=CVE-2024-23837, https://ubuntu.com/security/notices/USN-7814-1
Affected packages
Package
Name: libhtp
Purl: pkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
