A carefully crafted invalid TLS handshake can cause Apache Traffic Server (ATS) to segfault. This affects version 6.2.2. To resolve this issue users running 6.2.2 should upgrade to 6.2.3 or later versions.
References
Link | Resource |
---|---|
https://lists.apache.org/thread.html/ce404d2fe16cc59085ece5a6236ccd1549def471a2a9508198d966b1@%3Cusers.trafficserver.apache.org%3E | Vendor Advisory |
https://github.com/apache/trafficserver/pull/2147 | Patch Third Party Advisory |
http://www.securityfocus.com/bid/105183 | Third Party Advisory VDB Entry |
Configurations
Information
Published : 2018-08-29 06:29
Updated : 2018-10-17 15:17
NVD link : CVE-2018-8022
Mitre link : CVE-2018-8022
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
apache
- traffic_server