trafficserver -- unspecified vulnerability

Affected packages
trafficserver < 5.0.1


VuXML ID 6318b303-3507-11e4-b76c-0011d823eebd
Discovery 2014-07-23
Entry 2014-09-05

Bryan Call reports:

Below is our announcement for the security issue reported to us from Yahoo! Japan. All versions of Apache Traffic Server are vulnerable. We urge users to upgrade to either or 5.0.1 immediately.

This fixes CVE-2014-3525 and limits access to how the health checks are performed.


