Release date: 2012-03-22
Updated on: 2012-03-26
Affected Systems:
Apache Group Traffic Server
Description:
--------------------------------------------------------------------------------
Bugtraq id: 52696
Cve id: CVE-2012-0256
Apache Traffic Server (ATS or TS) is a high-performance, scalable, modular HTTP/1.1 cache proxy Server.
Apache Traffic Server has a heap overflow vulnerability in the implementation of the HTTP protocol. by sending specially crafted HTTP messages to the affected Server, access is denied or arbitrary code is executed.
<* Source: Codenomicon CROSS project
Link: http://seclists.org/fulldisclosure/2012/Mar/260
Https://www.cert.fi/en/reports/2012/vulnerability612884.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://httpd.apache.org/