Lucene search

K
cvelistApacheCVELIST:CVE-2020-13950
HistoryJun 10, 2021 - 7:10 a.m.

CVE-2020-13950 mod_proxy_http NULL pointer dereference

2021-06-1007:10:21
apache
www.cve.org
5
apache http server
mod_proxy_http
null pointer dereference
denial of service
cve-2020-13950

AI Score

8.4

Confidence

High

EPSS

0.006

Percentile

78.9%

Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using both Content-Length and Transfer-Encoding headers, leading to a Denial of Service

CNA Affected

[
  {
    "product": "Apache HTTP Server",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "status": "affected",
        "version": "2.4.46"
      },
      {
        "status": "affected",
        "version": "2.4.43"
      },
      {
        "status": "affected",
        "version": "2.4.41"
      }
    ]
  }
]

References