Candidate: CVE-2016-5396 PublicDate: 2017-04-17 18:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5396 https://issues.apache.org/jira/browse/TS-5019 http://www.openwall.com/lists/oss-security/2017/04/17/7 https://github.com/apache/trafficserver/pull/1160 https://github.com/apache/trafficserver/pull/1162 Description: Apache Traffic Server 6.0.0 to 6.2.0 are affected by an HPACK Bomb Attack. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_trafficserver: upstream_trafficserver: released (7.0.0-1) precise_trafficserver: not-affected (code not present) trusty_trafficserver: not-affected (code not present) trusty/esm_trafficserver: DNE (trusty was not-affected [code not present]) vivid/stable-phone-overlay_trafficserver: DNE vivid/ubuntu-core_trafficserver: DNE xenial_trafficserver: not-affected (code not present) yakkety_trafficserver: not-affected (code not present) zesty_trafficserver: not-affected (7.0.0-5) devel_trafficserver: not-affected (7.0.0-5)