Project

General

Profile

Actions

Security #6533

closed

Security #6444: http1: quadratic complexity from infinite folded headers

http1: quadratic complexity from infinite folded headers (7.0.x backport)

Added by OISF Ticketbot 6 months ago. Updated 2 months ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Label:
Git IDs:

20ac301d801cdf01b3f021cca08a22a87f477c4a

Severity:
CRITICAL
Disclosure Date:
Actions #1

Updated by Jason Ish 4 months ago

  • Severity changed from MODERATE to CRITICAL
Actions #2

Updated by Victor Julien 3 months ago

  • Status changed from Assigned to Resolved
Actions #3

Updated by Victor Julien 3 months ago

  • CVE set to 2024-23837

Issue is in libhtp and is fixed in libhtp 0.5.46.

Actions #4

Updated by Philippe Antoine 3 months ago

  • Status changed from Resolved to Closed
  • Git IDs updated (diff)
Actions #5

Updated by Victor Julien 2 months ago

  • Private changed from Yes to No
Actions

Also available in: Atom PDF