Back to search
CVE-2020-9494
Published: Jun 24, 2020
Modified: Aug 4, 2024
PUBLISHED
Description
Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the server to allocate a large amount of memory and spin the thread.
| Vendor | Product | Versions |
|---|---|---|
Apache Software Foundation | Apache Traffic Server | affected 6.0.0 to 6.2.3affected 7.0.0 to 7.1.10affected 8.0.0 to 8.0.7 |
References
DSA-4710
vendor-advisory
x_refsource_DEBIAN
[oss-security] 20210301 CVE-2021-25329: Apache Tomcat Incomplete fix for CVE-2020-9484
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now