CVE-2024-50305

Valid Host header field can cause Apache Traffic Server to crash on some platforms. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5. Users are recommended to upgrade to version 9.2.6, which fixes the issue, or 10.0.2, which does not have the issue.
Configurations

No configuration.

History

14 Nov 2024, 19:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-120
Summary
  • (es) Un campo de encabezado de host válido puede provocar que Apache Traffic Server se bloquee en algunas plataformas. Este problema afecta a Apache Traffic Server: desde la versión 9.2.0 hasta la 9.2.5. Se recomienda a los usuarios actualizar a la versión 9.2.6, que soluciona el problema, o a la versión 10.0.2, que no lo tiene.

14 Nov 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-14 10:15

Updated : 2024-11-15 13:58


NVD link : CVE-2024-50305

Mitre link : CVE-2024-50305

CVE.ORG link : CVE-2024-50305


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')