CVE-2017-7670

Source
https://cve.org/CVERecord?id=CVE-2017-7670
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7670.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-7670
Aliases
Published
2017-07-10T18:29:00.253Z
Modified
2026-04-10T04:00:59.771279Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

The Traffic Router component of the incubating Apache Traffic Control project is vulnerable to a Slowloris style Denial of Service attack. TCP connections made on the configured DNS port will remain in the ESTABLISHED state until the client explicitly closes the connection or Traffic Router is restarted. If connections remain in the ESTABLISHED state indefinitely and accumulate in number to match the size of the thread pool dedicated to processing DNS requests, the thread pool becomes exhausted. Once the thread pool is exhausted, Traffic Router is unable to service any DNS request, regardless of transport protocol.

References

Affected packages

Git / github.com/apache/incubator-trafficcontrol

Affected ranges

Type
GIT
Repo
https://github.com/apache/incubator-trafficcontrol
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.8.0"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.8.1-rc0"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.0.0-rc1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.0.0-rc2"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.0.0-rc3"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.0.0-rc4"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.0.0-rc5"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.0.0-rc6"
        }
    ]
}

Affected versions

1.*
1.1.0-release
1.1.1-hotfix
1.1.1-release
1.1.2-release
RELEASE-1.*
RELEASE-1.4.0-RC0
RELEASE-1.5.0-RC0
RELEASE-1.6.0-RC0
RELEASE-1.7.0-RC0
RELEASE-1.8.0
RELEASE-1.8.0-RC0
RELEASE-1.8.0-RC1
RELEASE-1.8.0-RC11
RELEASE-1.8.0-RC2
RELEASE-1.8.0-RC3
RELEASE-1.8.0-RC4
RELEASE-1.8.0-RC5
RELEASE-1.8.0-RC6
RELEASE-1.8.0-RC7
RELEASE-1.8.0-RC8
RELEASE-1.8.0-RC9
RELEASE-1.8.1
RELEASE-1.8.1-RC0
RELEASE-2.*
RELEASE-2.0.0
RELEASE-2.0.0-RC1
RELEASE-2.0.0-RC2
RELEASE-2.0.0-RC3
RELEASE-2.0.0-RC4
RELEASE-2.0.0-RC5
RELEASE-2.0.0-RC6
traffic_monitor-1.*
traffic_monitor-1.1.1
traffic_ops-release-1.*
traffic_ops-release-1.1.2
traffic_ops-release-1.1.3
traffic_ops-release-1.1.5
traffic_ops-release-1.1.6
traffic_router-1.*
traffic_router-1.1.1
traffic_router-1.1.2
v1.*
v1.1.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7670.json"