CVE Vulnerabilities

CVE-2019-17420

Incomplete Cleanup

Published: Oct 10, 2019 | Modified: Jul 21, 2021
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

In OISF LibHTP before 0.5.31, as used in Suricata 4.1.4 and other products, an HTTP protocol parsing error causes the http_header signature to not alert on a response with a single rn ending.

Weakness

The product does not properly “clean up” and remove temporary or supporting resources after they have been used.

Affected Software

Name Vendor Start Version End Version
Libhtp Oisf * 0.5.31 (excluding)
Suricata Suricata-ids 4.1.4 (including) 4.1.4 (including)
Libhtp Ubuntu bionic *
Libhtp Ubuntu disco *
Libhtp Ubuntu eoan *
Libhtp Ubuntu trusty *
Libhtp Ubuntu upstream *
Libhtp Ubuntu xenial *

Potential Mitigations

References