CVE-2024-23837: LibHTP unbounded folded header handling leads to denial service
Published Feb 26, 2024
·Updated
LibHTP is a security-aware parser for the HTTP protocol. Crafted traffic can cause excessive processing time of HTTP headers, leading to denial of service. This issue is addressed in 0.5.46.
Affected Software
4 affected components
LibHTP LibHTP<0.5.46
OISF LibHTP<0.5.46
Fedoraproject Fedora=38
Fedoraproject Fedora=39
Remediation
Event History
Feb 26, 2024
CVE Published
via MITRE·04:17 PM
Data Sourced
via MITRE·04:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:27 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-23837?
CVE-2024-23837 has a severity rating that indicates it can lead to denial of service due to excessive processing time.
2
How do I fix CVE-2024-23837?
To fix CVE-2024-23837, upgrade LibHTP to version 0.5.46 or later.
3
What causes the vulnerability CVE-2024-23837?
CVE-2024-23837 is caused by crafted traffic that can lead to excessive processing time of HTTP headers in LibHTP.
4
Which versions of LibHTP are affected by CVE-2024-23837?
Versions of LibHTP prior to 0.5.46 are affected by CVE-2024-23837.
5
What type of attack is CVE-2024-23837 associated with?
CVE-2024-23837 is associated with a denial of service attack that exploits the HTTP header processing.