CVE-2016-5396Software Foundation Apache Traffic Server vulnerability

CWE-3995 documents5 sources
Severity
7.5HIGHNVD
EPSS
1.8%
top 17.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 17
Latest updateMay 17

Description

Apache Traffic Server 6.0.0 to 6.2.0 are affected by an HPACK Bomb Attack.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-4r32-4xgr-6w96: Apache Traffic Server 62022-05-17
CVEList
CVE-2016-5396: Apache Traffic Server 62017-04-17
OSV
CVE-2016-5396: Apache Traffic Server 62017-04-17

📋Vendor Advisories

1
Debian
CVE-2016-5396: trafficserver - Apache Traffic Server 6.0.0 to 6.2.0 are affected by an HPACK Bomb Attack.2016
CVE-2016-5396 — HIGH severity | cvebase