Bug 1179203 (CVE-2014-10022) - CVE-2014-10022 trafficserver: incorrect handling of "Max-Forwards" header
Summary: CVE-2014-10022 trafficserver: incorrect handling of "Max-Forwards" header
Status: NEW
Alias: CVE-2014-10022
Product: Security Response
Classification: Other
Component: vulnerability   
(Show other bugs)
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard: impact=moderate,public=20150106,repor...
Keywords: Security
Depends On: 1179204 1179205
Blocks:
TreeView+ depends on / blocked
 
Reported: 2015-01-06 12:39 UTC by Martin Prpič
Modified: 2015-02-25 14:18 UTC (History)
1 user (show)

Fixed In Version: trafficserver 5.1.2
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

Description Martin Prpič 2015-01-06 12:39:36 UTC
The following issue was reported against Traffic Server 5.0.0 - 5.1.1:

Receiving a HTTP TRACE request containing a "Max-Forwards" header with a value of "0" will cause the traffic_server process to crash with an assertion failure, even in release builds.

The parent process, traffic_manager, will restart the traffic_server process when it sees that it has crashed. However, it takes several seconds before the new process is ready to handle requests, during which the server appears unresponsive to the outside world. Also, traffic_manager will queue incoming requests until the new process is ready to handle them. These queued requests might consist of more of the same request that caused the traffic_server process to crash in the first place. This allows a remote attacker to perform an effective DoS of the server with very little resources by simply sending the crashing request repeatedly.

References:

Bug entry: https://issues.apache.org/jira/browse/TS-3223
Fix: https://git-wip-us.apache.org/repos/asf?p=trafficserver.git;a=commit;h=8b5f0345dade6b2822d9b52c8ad12e63011a5c12
Release notes: https://issues.apache.org/jira/secure/ReleaseNote.jspa?version=12327089&styleName=Html&projectId=12310963
CVE request: http://seclists.org/oss-sec/2015/q1/69

Comment 1 Martin Prpič 2015-01-06 12:40:01 UTC
Created trafficserver tracking bugs for this issue:

Affects: fedora-21 [bug 1179204]
Affects: epel-7 [bug 1179205]


Note You need to log in before you can comment on or make changes to this bug.