First published: Mon Apr 17 2017(Updated: )
Apache Traffic Server 6.0.0 to 6.2.0 are affected by an HPACK Bomb Attack.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Traffic Server | =6.0.0 | |
Apache Traffic Server | =6.1.0 | |
Apache Traffic Server | =6.1.1 | |
Apache Traffic Server | =6.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5396 has been rated as a medium severity vulnerability due to its potential impact on service availability.
To fix CVE-2016-5396, you should upgrade Apache Traffic Server to version 6.3.0 or later.
CVE-2016-5396 is associated with HPACK Bomb attacks which can lead to denial-of-service conditions.
CVE-2016-5396 affects Apache Traffic Server versions 6.0.0 through 6.2.0.
The impact of CVE-2016-5396 can result in excessive memory consumption, potentially degrading system performance or causing crashes.