CVE-2021-43082: heap-buffer-overflow with stats-over-http plugin
Published Nov 3, 2021
·Updated
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the stats-over-http plugin of Apache Traffic Server allows an attacker to overwrite memory. This issue affects Apache Traffic Server 9.1.0.
Affected Software
2 affected components
Apache Traffic Server>=8.0.0<=8.1.2
Apache Traffic Server>=9.0.0<=9.1.0
Remediation
Event History
Nov 3, 2021
CVE Published
via MITRE·03:20 PM
Data Sourced
via MITRE·03:20 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-43082.
2
What is the title of this vulnerability?
The title of this vulnerability is 'Buffer Copy without Checking Size of Input (Classic Buffer Overflow) vulnerability in the stats-over-http plugin of Apache Traffic Server'.
3
What is the severity of CVE-2021-43082?
The severity of CVE-2021-43082 is critical with a CVSS score of 9.8.
4
Which software versions are affected by this vulnerability?
This vulnerability affects Apache Traffic Server versions 8.0.0 to 8.1.2 and version 9.0.0 to 9.1.0.
5
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by overwriting memory through the stats-over-http plugin of Apache Traffic Server.