Critical severity9.8NVD Advisory· Published Nov 3, 2021· Updated Jun 17, 2026
CVE-2021-43082
CVE-2021-43082
Description
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the stats-over-http plugin of Apache Traffic Server allows an attacker to overwrite memory. This issue affects Apache Traffic Server 9.1.0.
Affected products
4- Range: =9.1.0
- Range: =9.1.0
cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*range: >=8.0.0,<=8.1.2
- (no CPE)range: 9.1.0
Patches
Vulnerability mechanics
References
1- lists.apache.org/thread/k01797hyncx53659wr3o72s5cvkc3164nvdMailing ListPatchVendor Advisory
News mentions
0No linked articles in our index yet.