LibHTP是一款安全感知解析器。该产品主要用于HTTP协议等。 LibHTP 0.5.46 版本之前存在安全漏洞,该漏洞源于精心设计的流量可能会导致 HTTP 标头的处理时间过长,从而导致拒绝服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2024-23835 | 7.5 HIGH | Suricata's pgsql: memory exhaustion use on record parsing |
| CVE-2024-23836 | 7.5 HIGH | crafted traffic can cause denial of service |
| CVE-2024-23839 | 7.1 HIGH | Suricata http: heap use after free with http.request_header and http.response_header keyw |
| CVE-2024-24568 | 5.3 MEDIUM | Suricata http2: header handling evasion |
No comments yet