CVE-2018-10243: Critical severity libhtp vulnerability
Published Apr 4, 2019
·Updated
htpparseauthorizationdigest in htpparsers.c in LibHTP 0.5.26 allows remote attackers to cause a heap-based buffer over-read via an authorization digest header.
Affected Software
1 affected component
OISF LibHTP=0.5.26
Event History
Apr 4, 2019
CVE Published
via MITRE·03:10 PM
Data Sourced
via MITRE·03:10 PM
Description
Frequently Asked Questions
1
What is CVE-2018-10243?
CVE-2018-10243 is a vulnerability in LibHTP 0.5.26 that allows remote attackers to cause a heap-based buffer over-read via an authorization digest header.
2
What is the severity of CVE-2018-10243?
The severity of CVE-2018-10243 is critical with a severity value of 9.8.
3
How does CVE-2018-10243 impact LibHTP 0.5.26?
CVE-2018-10243 allows remote attackers to cause a heap-based buffer over-read in LibHTP 0.5.26.
4
What software versions are affected by CVE-2018-10243?
LibHTP 0.5.26 is affected by CVE-2018-10243.
5
How do I patch or fix CVE-2018-10243?
To fix CVE-2018-10243, it is recommended to update to a version of LibHTP that is not affected, if available, or apply any patches provided by the software vendor.