Actions
Security #6444
closedhttp1: quadratic complexity from infinite folded headers
Git IDs:
20ac301d801cdf01b3f021cca08a22a87f477c4a
Severity:
CRITICAL
Disclosure Date:
01/24/2024
Description
Found by oss-fuzz with quadfuzz
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=63600&q=label%3AProj-suricata
POC to reproduce is
GET / HTTP/1.1 Host: localhost Header: a b b b b
never stopping
Files
Actions