LibHTP is a security-aware parser for the HTTP protocol and the related bits and pieces. Version 0.5.46 may parse malformed request traffic, leading to excessive CPU usage. Version 0.5.47 contains a patch for the issue. No known workarounds are available.
{
"cwe_ids": [
"CWE-770"
]
}[
{
"signature_version": "v1",
"deprecated": false,
"source": "https://github.com/oisf/libhtp/commit/bf618ec7f243cebfb0f7e84c3cb158955cb32b4d",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"318172770935594959350941458745435307763",
"135239512933602376594045183615727728699",
"131700058990156315402314416600437322377",
"277994319879901349994914593103939313737"
]
},
"target": {
"file": "test/test_main.cpp"
},
"id": "CVE-2024-28871-3ed3ea6c"
},
{
"signature_version": "v1",
"deprecated": false,
"source": "https://github.com/oisf/libhtp/commit/bf618ec7f243cebfb0f7e84c3cb158955cb32b4d",
"signature_type": "Function",
"digest": {
"function_hash": "148640750141087490866965115654957542471",
"length": 354.0
},
"target": {
"function": "TEST_F",
"file": "test/test_main.cpp"
},
"id": "CVE-2024-28871-42916d96"
},
{
"signature_version": "v1",
"deprecated": false,
"source": "https://github.com/oisf/libhtp/commit/bf618ec7f243cebfb0f7e84c3cb158955cb32b4d",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"267359046665290570769923342758498273095",
"303551294191400035276263804370023306921",
"119839181945903624091477649627408790864",
"161212438092718958504047245052704100794",
"150200054387931348240854522730784242602",
"207265992600273278446008837170369875565",
"94233397943067680948929258014963379952",
"177308729534991442599318098923060054484",
"147060639569616060088023905671536173844",
"74451318637906718655269567190115454574",
"9565752617086491266711890594113080014",
"257183742756321029938664592568116238449",
"163640541665630402471706784285028629",
"327832901355841139650099125053069665217",
"298221389295221802504942701590661372085"
]
},
"target": {
"file": "htp/htp_request.c"
},
"id": "CVE-2024-28871-5f9a7a33"
},
{
"signature_version": "v1",
"deprecated": false,
"source": "https://github.com/oisf/libhtp/commit/bf618ec7f243cebfb0f7e84c3cb158955cb32b4d",
"signature_type": "Function",
"digest": {
"function_hash": "42034569953756389800674741515598562518",
"length": 831.0
},
"target": {
"function": "htp_connp_REQ_PROTOCOL",
"file": "htp/htp_request.c"
},
"id": "CVE-2024-28871-7dd59a4d"
}
]