Lucene search

K
kasperskyKaspersky LabKLA12369
HistoryJun 01, 2021 - 12:00 a.m.

KLA12369 Multiple vulnerabilities in Apache HTTP Server

2021-06-0100:00:00
Kaspersky Lab
threats.kaspersky.com
36

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

8.3 High

AI Score

Confidence

High

0.706 High

EPSS

Percentile

98.1%

Multiple vulnerabilities were found in Apache HTTP Server. Malicious users can exploit these vulnerabilities to cause denial of service, bypass security restrictions.

Below is a complete list of vulnerabilities:

  1. Heap overflow vulnerability in mod_session can be exploited via special crafted SessionHandler to cause denial of service.
  2. NULL pointer dereference vulnerability in mod_session can be exploited via special crafted coockie header to cause denial of service.
  3. Security bypass vulnerability vulnerability in httpd can be exploited to bypass security restrictions.
  4. NULL pointer dereference vulnerability in mod_http2 can be exploited via special crafted HTTP/2 request to cause denial of service.
  5. Security bypass vulnerability in mod_proxy_wstunnel can be exploited to bypass security restrictions.
  6. Stack overflow vulnerability in mod_auth_digest can be exploited bia specia crafted digest to cause denial of service.
  7. Security bypass vulnerability in “MergeSlashes OFF” can be exploited via special crafted URL to bypass security restrictions.
  8. NULL pointer dereference vulnerability in mod_proxy_http can be exploited via special crafted requests to cause denial of service.

Original advisories

Fixed in Apache HTTP Server 2.4.48

Related products

Apache-HTTP-Server

CVE list

CVE-2021-26691 critical

CVE-2021-26690 critical

CVE-2020-13938 high

CVE-2021-31618 critical

CVE-2019-17567 high

CVE-2020-35452 high

CVE-2021-30641 high

CVE-2020-13950 critical

Solution

Update to the latest version

Download Apache HTTP Server

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

  • DoS

Denial of service. Exploitation of vulnerabilities with this impact can lead to loss of system availability or critical functional fault.

  • SB

Security bypass. Exploitation of vulnerabilities with this impact can lead to performing actions restricted by current security settings.

  • SUI

Spoof user interface. Exploitation of vulnerabilities with this impact can lead to changes in user interface to beguile user into inaccurate behavior.

Affected Products

  • Apache HTTP Server earlier than 2.4.48

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

8.3 High

AI Score

Confidence

High

0.706 High

EPSS

Percentile

98.1%