Allocation of Resources Without Limits or Throttling in libhtp - CVE-2024-23837
Published: March 18, 2024
Vulnerability identifier: #VU87579
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-23837
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to unbounded folded header handling. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.
Affected software
libhtp
Fedora
Ubuntu
libhtp (Ubuntu package)
suricata
Kaspersky Anti Targeted Attack
Fedora
Ubuntu
libhtp (Ubuntu package)
suricata
Kaspersky Anti Targeted Attack
How to mitigate CVE-2024-23837
Install updates from vendor's website.
libhtp - update to 0.5.46
libhtp (Ubuntu package) - addressed in versions 0.5.15-1ubuntu0.1~esm1, 1:0.5.26-1ubuntu0.1~esm1, 1:0.5.32-1ubuntu0.1~esm1, 1:0.5.39-1ubuntu0.1~esm1, 1:0.5.46-1ubuntu2+esm1, 1:0.5.49-1ubuntu0.1
Kaspersky Anti Targeted Attack - update to 6.0.2
suricata - addressed in versions 6.0.16-1.el8, 6.0.16-1.el9, 6.0.16-1.fc38, 6.0.16-1.fc39
libhtp (Ubuntu package) - addressed in versions 0.5.15-1ubuntu0.1~esm1, 1:0.5.26-1ubuntu0.1~esm1, 1:0.5.32-1ubuntu0.1~esm1, 1:0.5.39-1ubuntu0.1~esm1, 1:0.5.46-1ubuntu2+esm1, 1:0.5.49-1ubuntu0.1
Kaspersky Anti Targeted Attack - update to 6.0.2
suricata - addressed in versions 6.0.16-1.el8, 6.0.16-1.el9, 6.0.16-1.fc38, 6.0.16-1.fc39
External References
- https://github.com/OISF/libhtp/security/advisories/GHSA-f9wf-rrjj-qx8m
- https://github.com/OISF/libhtp/commit/20ac301d801cdf01b3f021cca08a22a87f477c4a
- https://redmine.openinfosecfoundation.org/issues/6444
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GOCOBFUTIFHOP2PZOH4ENRFXRBHIRKK4/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZXJIT7R53ZXROO3I256RFUWTIW4ECK6P/