CVE-2017-5660
Summary
| CVE | CVE-2017-5660 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-02-27 20:29:00 UTC |
| Updated | 2023-11-07 02:49:00 UTC |
| Description | There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the Host header and line folding. This can have issues when interacting with upstream proxies and the wrong host being used. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Traffic Server | 6.2.1 | All | All | All |
| Application | Apache | Traffic Server | 6.2.1 | rc0 | All | All |
| Application | Apache | Traffic Server | 6.2.2 | All | All | All |
| Application | Apache | Traffic Server | 6.2.2 | rc0 | All | All |
| Application | Apache | Traffic Server | 7.0.0 | All | All | All |
| Application | Apache | Traffic Server | 7.0.0 | rc0 | All | All |
| Application | Apache | Traffic Server | 7.0.0 | rc1 | All | All |
| Application | Apache | Traffic Server | 7.0.0 | rc2 | All | All |
| Application | Apache | Traffic Server | 6.2.1 | All | All | All |
| Application | Apache | Traffic Server | 6.2.1 | rc0 | All | All |
| Application | Apache | Traffic Server | 6.2.2 | All | All | All |
| Application | Apache | Traffic Server | 6.2.2 | rc0 | All | All |
| Application | Apache | Traffic Server | 7.0.0 | All | All | All |
| Application | Apache | Traffic Server | 7.0.0 | rc0 | All | All |
| Application | Apache | Traffic Server | 7.0.0 | rc1 | All | All |
| Application | Apache | Traffic Server | 7.0.0 | rc2 | All | All |
| Application | Apache | Traffic Server | All | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian -- Security Information -- DSA-4128-1 trafficserver | DEBIAN | www.debian.org | Third Party Advisory |
| Pony Mail! | MLIST | lists.apache.org | Vendor Advisory |
| Pony Mail! | lists.apache.org | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.