Resource exhaustion in libhtp - CVE-2024-45797
Published: October 16, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when handling HTTP requests. A remote attacker can send specially crafted HTTP requests to the application and perform a denial of service (DoS) attack.
Affected software
Ubuntu
libhtp (Ubuntu package)
How to mitigate CVE-2024-45797
libhtp (Ubuntu package) - addressed in versions 0.5.15-1ubuntu0.1~esm1, 1:0.5.26-1ubuntu0.1~esm1, 1:0.5.32-1ubuntu0.1~esm1, 1:0.5.39-1ubuntu0.1~esm1, 1:0.5.46-1ubuntu2+esm1, 1:0.5.49-1ubuntu0.1