Apache Traffic Server: Invalid Range header causes a crash
Vulnerability Description
Improper input validation vulnerability on the range header in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: through 9.2.1.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-47185
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Katsutoshi Ikenoya
References
- https://lists.apache.org/thread/jsl6dfdgs1mjjo1mbtyflyjr7xftswhc
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BOTOM2MFKOLK46Q3BQHO662HTPZFRQUC/
- https://lists.debian.org/debian-lts-announce/2023/09/msg00042.html
- https://www.debian.org/security/2023/dsa-5549
More from Apache Software Foundation
View All →Affected Vendor
Apache Software Foundation
View all reports →