CVE-2016-5396: High severity apache traffic server vulnerability
Published Apr 17, 2017
·Updated
Apache Traffic Server 6.0.0 to 6.2.0 are affected by an HPACK Bomb Attack.
Affected Software
4 affected components
Apache Traffic Server=6.0.0
Apache Traffic Server=6.1.0
Apache Traffic Server=6.1.1
Apache Traffic Server=6.2.0
Remediation
Patch Available
Event History
Apr 17, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-5396?
CVE-2016-5396 has been rated as a medium severity vulnerability due to its potential impact on service availability.
2
How do I fix CVE-2016-5396?
To fix CVE-2016-5396, you should upgrade Apache Traffic Server to version 6.3.0 or later.
3
What types of attacks are associated with CVE-2016-5396?
CVE-2016-5396 is associated with HPACK Bomb attacks which can lead to denial-of-service conditions.
4
Which versions of Apache Traffic Server are affected by CVE-2016-5396?
CVE-2016-5396 affects Apache Traffic Server versions 6.0.0 through 6.2.0.
5
What is the impact of CVE-2016-5396 on system performance?
The impact of CVE-2016-5396 can result in excessive memory consumption, potentially degrading system performance or causing crashes.