CVE-2024-50305
Publication date 14 November 2024
Last updated 20 November 2024
Ubuntu priority
Valid Host header field can cause Apache Traffic Server to crash on some platforms. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5. Users are recommended to upgrade to version 9.2.6, which fixes the issue, or 10.0.2, which does not have the issue.
Status
Package | Ubuntu Release | Status |
---|---|---|
trafficserver | 24.10 oracular |
Needs evaluation
|
24.04 LTS noble |
Needs evaluation
|
|
22.04 LTS jammy |
Needs evaluation
|
|
20.04 LTS focal |
Needs evaluation
|
|
18.04 LTS bionic |
Needs evaluation
|
|
16.04 LTS xenial |
Needs evaluation
|
References
Other references
- https://www.cve.org/CVERecord?id=CVE-2024-50305
- https://www.openwall.com/lists/oss-security/2024/11/13/1
- https://github.com/apache/trafficserver/issues/8461
- https://github.com/apache/trafficserver/commit/5e39658f7c0bc91613468c9513ba22ede1739d7e (9.2.6-rc0)
- https://github.com/apache/trafficserver/commit/055ca11c2842a64bf7df8d547515670e1a04afc1 (master)
- https://lists.apache.org/thread/y15fh6c7kyqvzm0f9odw7c5jh4r4np0y