Lucene search

K
f5F5F5:K27129140
HistoryApr 14, 2022 - 12:00 a.m.

K27129140 : mod_auth_digest vulnerability CVE-2020-35452

2022-04-1400:00:00
my.f5.com
43

8.3 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

55.9%

Security Advisory Description

Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP Server team could create one, though some particular compiler and/or compilation option might make it possible, with limited consequences anyway due to the size (a single byte) and the value (zero byte) of the overflow (CVE-2020-35452)

Impact

There is no impact; F5 products are not affected by this vulnerability.