Apache Traffic Server HPACK Decompression and Chunked Data Processing Flaws Let Remote Users Deny Service
|
SecurityTracker Alert ID: 1038275 |
SecurityTracker URL: http://securitytracker.com/id/1038275
|
CVE Reference:
CVE-2016-5396, CVE-2017-5659
(Links to External Site)
|
Date: Apr 17 2017
|
Impact:
Denial of service via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): prior to 6.2.1
|
Description:
Two vulnerabilities were reported in Apache Traffic Server. A remote user can cause denial of service conditions on the target system.
A remote user can send specially crafted HPACK data to cause the decompression process to consume excessive memory on the target system [CVE-2016-5396]. This exploit method is referred to as an HPACK Bomb Attack.
A remote user can send specially crafted chunked data to cause the target service to crash [CVE-2017-5659].
Masaori Koshiba and Syeda Persia Aziz reported these vulnerabilities.
|
Impact:
A remote user can cause denial of service conditions.
|
Solution:
The vendor has issued a fix (6.2.1, 7.0.0).
The vendor advisories are available at:
https://issues.apache.org/jira/browse/TS-4507
https://issues.apache.org/jira/browse/TS-5019
|
Vendor URL: trafficserver.apache.org/ (Links to External Site)
|
Cause:
Resource error, State error
|
Underlying OS: Linux (Any), UNIX (Any), Windows (Any)
|
|
Message History:
None.
|
Source Message Contents
|
|
[Original Message Not Available for Viewing]
|
|