Heap-based Buffer Over-read in LibHTP 0.5.26 via Authorization Digest Header

Heap-based Buffer Over-read in LibHTP 0.5.26 via Authorization Digest Header

CVE-2018-10243 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

htp_parse_authorization_digest in htp_parsers.c in LibHTP 0.5.26 allows remote attackers to cause a heap-based buffer over-read via an authorization digest header.

Learn more about our Web Application Penetration Testing UK.