Project

General

Profile

Actions

Security #6757

closed
PA PA

libhtp: quadratic complexity checking after request line missing protocol

Security #6757: libhtp: quadratic complexity checking after request line missing protocol

Added by Philippe Antoine about 2 years ago. Updated almost 2 years ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Label:
Git IDs:
Severity:
CRITICAL
Disclosure Date:
05/08/2024


Subtasks 2 (0 open2 closed)

Security #6758: libhtp: quadratic complexity checking after request line mission protocol (6.0.x backport)ClosedPhilippe AntoineActions
Security #6759: libhtp: quadratic complexity checking after request line mission protocol (7.0.x backport)ClosedPhilippe AntoineActions

Related issues 2 (0 open2 closed)

Related to Suricata - Task #6769: libhtp 0.5.47ClosedVictor JulienActions
Related to Suricata - Feature #6856: http: anomaly when request line is missing protocolClosedPhilippe AntoineActions

OT Updated by OISF Ticketbot about 2 years ago Actions #1

  • Subtask #6758 added

OT Updated by OISF Ticketbot about 2 years ago Actions #2

  • Label deleted (Needs backport to 6.0)

OT Updated by OISF Ticketbot about 2 years ago Actions #3

  • Subtask #6759 added

OT Updated by OISF Ticketbot about 2 years ago Actions #4

  • Label deleted (Needs backport to 7.0)

PA Updated by Philippe Antoine about 2 years ago Actions #5

  • Status changed from New to In Review
  • Label Needs backport to 6.0, Needs backport to 7.0 added

Gitlab MR

OT Updated by OISF Ticketbot about 2 years ago Actions #6

  • Label deleted (Needs backport to 6.0)

OT Updated by OISF Ticketbot about 2 years ago Actions #7

  • Label deleted (Needs backport to 7.0)

PA Updated by Philippe Antoine about 2 years ago Actions #8

  • Tracker changed from Bug to Security
  • Severity set to MODERATE
  • Disclosure Date set to 05/08/2024

PA Updated by Philippe Antoine about 2 years ago Actions #9

VJ Updated by Victor Julien about 2 years ago Actions #10

  • Subject changed from libhtp: quadratic complexity checking after request line mission protocol to libhtp: quadratic complexity checking after request line missing protocol

VJ Updated by Victor Julien about 2 years ago Actions #11

  • Severity changed from MODERATE to CRITICAL

PA Updated by Philippe Antoine about 2 years ago Actions #12

  • Related to Feature #6856: http: anomaly when request line is missing protocol added

VJ Updated by Victor Julien about 2 years ago Actions #13

  • CVE set to 2024-28871
Actions

Also available in: PDF Atom