Resource management error in Apache Traffic Server - CVE-2021-41585
Published: December 8, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of internal resources within the application when processing HTTP connections. A remote attacker can force the server to stop accepting new connections and perform a denial of service (DoS) attack.
Affected software
openEuler
trafficserver
trafficserver-debuginfo
trafficserver-devel
trafficserver-debugsource
trafficserver-perl
How to mitigate CVE-2021-41585
trafficserver - update to 9.1.0-4
trafficserver-debuginfo - update to 9.1.0-4
trafficserver-devel - update to 9.1.0-4
trafficserver-debugsource - update to 9.1.0-4
trafficserver-perl - update to 9.1.0-4