UBUNTU-CVE-2024-45797
Dashboard / Vulnerabilities / UBUNTU-CVE-2024-45797
UBUNTU-CVE-2024-45797
Summary:
Details: LibHTP is a security-aware parser for the HTTP protocol and the related bits and pieces. Prior to version 0.5.49, unbounded processing of HTTP request and response headers can lead to excessive CPU time and memory utilization, possibly leading to extreme slowdowns. This issue is addressed in 0.5.49.
References: https://ubuntu.com/security/CVE-2024-45797, https://www.cve.org/CVERecord?id=CVE-2024-45797, https://github.com/OISF/libhtp/security/advisories/GHSA-rqqp-24ch-248f, https://redmine.openinfosecfoundation.org/issues/7191, https://ubuntu.com/security/notices/USN-7814-1
Affected packages
Package
Name: libhtp
Purl: pkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
