Back to Database
Status published
Medium
CVE-2019-17420
In OISF LibHTP before 0.5.31, as used in Suricata 4.1.4...
Vulnerability Description
In OISF LibHTP before 0.5.31, as used in Suricata 4.1.4 and other products, an HTTP protocol parsing error causes the http_header signature to not alert on a response with a single \r\n ending.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-17420
Credits & Attribution
No credits recorded in the NVD database.
References
More from oisf
View All →CVE-2021-45098
An issue was discovered in Suricata before 6.0.4. It is...
High
7.5
CVE-2021-37592
Suricata before 5.0.8 and 6.x before 6.0.4 allows TCP evasion...
Critical
9.8
CVE-2021-35063
Suricata before 5.0.7 and 6.x before 6.0.3 has a "critical...
High
7.5
CVE-2020-19678
Directory Traversal vulnerability found in Pfsense v.2.1.3 and Pfsense Suricata...
Unknown
0
CVE-2019-18792
An issue was discovered in Suricata 5.0.0. It is possible...
Critical
9.1
Affected Vendor
oisf
View all reports →Affected Software
libhtp, suricata
Vulnerable Versions:
0, 4.1.4
Timeline
Official Publish:
October 9th, 2019
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.