Vulnerability Description
htp_parse_authorization_digest in htp_parsers.c in LibHTP 0.5.26 allows remote attackers to cause a heap-based buffer over-read via an authorization digest header.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oisf | Libhtp | 0.5.26 |
Related Weaknesses (CWE)
References
- https://lists.debian.org/debian-lts-announce/2019/04/msg00010.html
- https://suricata-ids.org/2018/07/18/suricata-4-0-5-available/Release NotesVendor Advisory
- https://lists.debian.org/debian-lts-announce/2019/04/msg00010.html
- https://suricata-ids.org/2018/07/18/suricata-4-0-5-available/Release NotesVendor Advisory
FAQ
What is CVE-2018-10243?
CVE-2018-10243 is a vulnerability with a CVSS score of 9.8 (CRITICAL). htp_parse_authorization_digest in htp_parsers.c in LibHTP 0.5.26 allows remote attackers to cause a heap-based buffer over-read via an authorization digest header.
How severe is CVE-2018-10243?
CVE-2018-10243 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-10243?
Check the references section above for vendor advisories and patch information. Affected products include: Oisf Libhtp.