Lucene search

K
httpdApache Team FoundationHTTPD:D9B9375C40939357C5F47F1B3F64F0A1
HistoryJun 16, 2020 - 12:00 a.m.

Apache Httpd < 2.4.44 : Push Diary Crash on Specifically Crafted HTTP/2 Header

2020-06-1600:00:00
Apache Team Foundation
httpd.apache.org
75

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.004

Percentile

73.5%

In Apache HTTP Server versions 2.4.20 to 2.4.43, when trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools.
Configuring the LogLevel of mod_http2 above “info” will mitigate this vulnerability for unpatched servers.

Affected configurations

Vulners
Node
apacheapache_httpdMatch2.4.43
OR
apacheapache_httpdMatch2.4.39
OR
apacheapache_httpdMatch2.4.38
OR
apacheapache_httpdMatch2.4.37
OR
apacheapache_httpdMatch2.4.35
OR
apacheapache_httpdMatch2.4.34
OR
apacheapache_httpdMatch2.4.33
OR
apacheapache_httpdMatch2.4.30
OR
apacheapache_httpdMatch2.4.29
OR
apacheapache_httpdMatch2.4.28
OR
apacheapache_httpdMatch2.4.27
OR
apacheapache_httpdMatch2.4.26
OR
apacheapache_httpdMatch2.4.25
OR
apacheapache_httpdMatch2.4.23
OR
apacheapache_httpdMatch2.4.20
VendorProductVersionCPE
apacheapache_httpd2.4.43cpe:2.3:a:apache:apache_httpd:2.4.43:*:*:*:*:*:*:*
apacheapache_httpd2.4.39cpe:2.3:a:apache:apache_httpd:2.4.39:*:*:*:*:*:*:*
apacheapache_httpd2.4.38cpe:2.3:a:apache:apache_httpd:2.4.38:*:*:*:*:*:*:*
apacheapache_httpd2.4.37cpe:2.3:a:apache:apache_httpd:2.4.37:*:*:*:*:*:*:*
apacheapache_httpd2.4.35cpe:2.3:a:apache:apache_httpd:2.4.35:*:*:*:*:*:*:*
apacheapache_httpd2.4.34cpe:2.3:a:apache:apache_httpd:2.4.34:*:*:*:*:*:*:*
apacheapache_httpd2.4.33cpe:2.3:a:apache:apache_httpd:2.4.33:*:*:*:*:*:*:*
apacheapache_httpd2.4.30cpe:2.3:a:apache:apache_httpd:2.4.30:*:*:*:*:*:*:*
apacheapache_httpd2.4.29cpe:2.3:a:apache:apache_httpd:2.4.29:*:*:*:*:*:*:*
apacheapache_httpd2.4.28cpe:2.3:a:apache:apache_httpd:2.4.28:*:*:*:*:*:*:*
Rows per page:
1-10 of 151

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.004

Percentile

73.5%