CVE-2017-7671: Input Validation
There is a DOS attack vulnerability in Apache Traffic Server (ATS) 5.2.0 to 5.3.2, 6.0.0 to 6.2.0, and 7.0.0 with the TLS handshake. This issue can cause the server to coredump.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-7671?
CVE-2017-7671 is a denial-of-service (DOS) attack vulnerability in Apache Traffic Server (ATS) versions 5.2.0 to 5.3.2, 6.0.0 to 6.2.0, and 7.0.0 with the TLS handshake that can cause the server to coredump.
What is the severity of CVE-2017-7671?
The severity of CVE-2017-7671 is high with a severity value of 7.5.
How does CVE-2017-7671 affect Apache Traffic Server?
CVE-2017-7671 affects Apache Traffic Server versions 5.2.0 to 5.3.2, 6.0.0 to 6.2.0, and 7.0.0 with the TLS handshake by allowing a DOS attack that can cause the server to coredump.
What is the fix for CVE-2017-7671?
To fix CVE-2017-7671, upgrade to a version of Apache Traffic Server that is not affected. For example, version 8.0.2 or higher for Debian Linux.
Where can I find more information about CVE-2017-7671?
You can find more information about CVE-2017-7671 in the following references: [GitHub Pull Request](https://github.com/apache/trafficserver/pull/1941), [Debian Security Tracker](https://security-tracker.debian.org/tracker/CVE-2017-7671), [Apache Traffic Server Mailing List](https://lists.apache.org/thread.html/203bdcf9bbb718f3dc6f7aaf3e2af632474d51fa9e7bfb7832729905@%3Cdev.trafficserver.apache.org%3E).