Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Debian DSA-4805-1 Moderate: Trafficserver Memory Disclosure and Poisoning

debian
Calendar Grey December 7, 2020
Debian Logo
Two security flaws resolved in Apache Traffic Server. Update promptly to bolster your defenses and safeguard against risks.
Two vulnerabilities were discovered in Apache Traffic Server, a reverse and forward proxy server: CVE-2020-17508

Summary

Two vulnerabilities were discovered in Apache Traffic Server, a reverse
and forward proxy server:

CVE-2020-17508

The ESI plugin was vulnerable to memory disclosure.

CVE-2020-17509

The negative cache option was vulnerable to cache poisoning.

For the stable distribution (buster), these problems have been fixed in
version 8.0.2+ds-1+deb10u4.

We recommend that you upgrade your trafficserver packages.

For the detailed security status of trafficserver please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/trafficserver

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Package: trafficserver
CVE ID: CVE-2020-17508 CVE-2020-17509

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here