There are 2 open security issues in bookworm.
2 issues left for the package maintainer to handle:
- CVE-2024-23837:
(needs triaging)
LibHTP is a security-aware parser for the HTTP protocol. Crafted traffic can cause excessive processing time of HTTP headers, leading to denial of service. This issue is addressed in 0.5.46.
- CVE-2024-45797:
(needs triaging)
LibHTP is a security-aware parser for the HTTP protocol and the related bits and pieces. Prior to version 0.5.49, unbounded processing of HTTP request and response headers can lead to excessive CPU time and memory utilization, possibly leading to extreme slowdowns. This issue is addressed in 0.5.49.
You can find information about how to handle these issues in the security team's documentation.