PT-2021-3574 · Apache · Apache Traffic Server

Masaori Koshiba

·

Published

2021-06-24

·

Updated

2021-09-20

·

CVE-2021-35474

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache Traffic Server versions 7.0.0 through 7.1.12 Apache Traffic Server versions 8.0.0 through 8.1.1 Apache Traffic Server versions 9.0.0 through 9.0.1
Description The issue is caused by a stack-based buffer overflow in the cachekey plugin of Apache Traffic Server. This can allow a remote attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For Apache Traffic Server versions 7.0.0 through 7.1.12, update to a version outside of this range to resolve the issue. For Apache Traffic Server versions 8.0.0 through 8.1.1, update to a version outside of this range to resolve the issue. For Apache Traffic Server versions 9.0.0 through 9.0.1, update to a version outside of this range to resolve the issue. As a temporary workaround, consider disabling the cachekey plugin until a patch is available.

Fix

Stack Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03675
CVE-2021-35474
DSA-4957-1

Affected Products

Apache Traffic Server