CVE-2019-17420: Medium severity libhtp vulnerability
Published Oct 9, 2019
·Updated
In OISF LibHTP before 0.5.31, as used in Suricata 4.1.4 and other products, an HTTP protocol parsing error causes the httpheader signature to not alert on a response with a single \r\n ending.
Affected Software
2 affected components
OISF LibHTP<0.5.31
Suricata-ids Suricata=4.1.4
Remediation
Patch Available
Patch Available
Event History
Oct 9, 2019
CVE Published
via MITRE·11:29 PM
Data Sourced
via MITRE·11:29 PM
Description
Frequently Asked Questions
1
What is CVE-2019-17420?
CVE-2019-17420 is a vulnerability in OISF LibHTP before version 0.5.31, as used in Suricata 4.1.4 and other products, that causes an HTTP protocol parsing error.
2
How does CVE-2019-17420 affect Suricata?
CVE-2019-17420 affects Suricata 4.1.4, causing the http_header signature to not alert on a response with a single \r\n ending.
3
What is the severity of CVE-2019-17420?
The severity of CVE-2019-17420 is medium with a CVSS score of 5.3.
4
How do I fix CVE-2019-17420 in OISF LibHTP and Suricata?
To fix CVE-2019-17420, update OISF LibHTP to version 0.5.31 and update Suricata to version 4.1.5 or later.
5
What is the CWE classification of CVE-2019-17420?
CVE-2019-17420 is classified under CWE-459 (Use of Inconsistent Cryptography).