Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-Id: <F4BD9382-D7C5-4322-BCDA-F555472B08F9@apache.org>
Date: Mon, 17 Apr 2017 16:13:04 -0700
From: Bryan Call <bcall@...che.org>
To: dev <dev@...fficserver.apache.org>,
 users@...fficserver.apache.org,
 announce@...fficserver.apache.org,
 security@...fficserver.apache.org,
 oss-security@...ts.openwall.com,
 bugtraq@...urityfocus.com,
 persia@...che.org
Subject: [ANNOUNCE] Chunking and content-length vulnerability in ATS -
 CVE-2017-5659

There is a vulnerability in ATS with chunking and content-length that can lead to a DoS attack.  Versions 6.2.0 and prior are affected.  Please upgrade to ATS 6.2.1 or 7.0.0.

Downloads:
	https://trafficserver.apache.org/downloads

Jira Ticket:
	https://issues.apache.org/jira/browse/TS-4819

CVE:
	https://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2017-5659


-Bryan

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.