PT-2019-15145 · Oisf+1 · Suricata+2
Ajaxtpm
·
Published
2019-10-09
·
Updated
2021-07-21
·
CVE-2019-17420
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OISF LibHTP versions prior to 0.5.31
Suricata version 4.1.4
Description
An HTTP protocol parsing error occurs in the affected software, causing the http header signature to not alert on a response with a single r
ending.
Recommendations
For OISF LibHTP versions prior to 0.5.31, update to version 0.5.31 or later to resolve the issue.
For Suricata version 4.1.4, consider updating to a newer version that incorporates the fix for OISF LibHTP.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Libhtp
Suricata