Security-Aware Parser Addresses CPU Time and Memory Utilization Issues
CVE-2024-45797

7.5HIGH

Key Information:

Vendor

Oisf

Status
Vendor
CVE Published:
16 October 2024

What is CVE-2024-45797?

LibHTP, a security-focused parser for handling the HTTP protocol, prior to version 0.5.49, is susceptible to an issue where unbounded processing of HTTP request and response headers can cause significant consumption of CPU resources and memory. This may lead to severe performance degradation, potentially impacting system responsiveness and availability. The vulnerability has been addressed in version 0.5.49, where enhanced limitations on header processing were implemented to mitigate related risks.

Affected Version(s)

libhtp < 0.5.49

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.
CVE-2024-45797 : Security-Aware Parser Addresses CPU Time and Memory Utilization Issues