Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Leif Hedstrom

#18997of 53,635
14.1Total CVSS
Vulnerabilities · 2
Medium
1
Critical
1
PT-2017-5879
9.8
2017-10-30
Apache · Apache Traffic Server · CVE-2014-3624
Name of the Vulnerable Software and Affected Versions: Apache Traffic Server version 5.1.x before 5.1.1 Description: The issue allows remote attackers to bypass access restrictions by leveraging the failure to properly tunnel remap requests using the CONNECT method. Recommendations: For Apache Traffic Server version 5.1.x before 5.1.1, update to version 5.1.1 or later to resolve the issue.
PT-2010-4430
4.3
2010-09-13
Apache · Apache Traffic Server · CVE-2010-2952
**Name of the Vulnerable Software and Affected Versions** Apache Traffic Server versions prior to 2.0.1 Apache Traffic Server versions 2.1.x prior to 2.1.2-unstable **Description** The issue makes it easier for man-in-the-middle attackers to poison the internal DNS cache via a crafted response, due to improper choice of DNS source ports and transaction IDs, and improper use of DNS query fields to validate responses. **Recommendations** For Apache Traffic Server versions prior to 2.0.1, update to version 2.0.1 or later. For Apache Traffic Server versions 2.1.x prior to 2.1.2-unstable, update to version 2.1.2-unstable or later.