framework/common/messageheaderparser.cpp in Tntnet before 2.2.1 allows remote attackers to obtain sensitive information via a header that ends in \n instead of \r\n, which prevents a null terminator from being added and causes Tntnet to include headers from other requests.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "libtntnet-dev",
"binary_version": "2.2.1-1"
},
{
"binary_name": "libtntnet12",
"binary_version": "2.2.1-1"
},
{
"binary_name": "tntnet",
"binary_version": "2.2.1-1"
},
{
"binary_name": "tntnet-demos",
"binary_version": "2.2.1-1"
},
{
"binary_name": "tntnet-doc",
"binary_version": "2.2.1-1"
},
{
"binary_name": "tntnet-runtime",
"binary_version": "2.2.1-1"
}
]
}