Lucene search

K
redhatcveRedhat.comRH:CVE-2020-9490
HistoryAug 11, 2020 - 8:13 p.m.

CVE-2020-9490

2020-08-1120:13:28
redhat.com
access.redhat.com
45

0.006 Low

EPSS

Percentile

78.6%

A flaw was found in Apache httpd in versions prior to 2.4.46. A specially crafted Cache-Digest header triggers negative argument to memmove() that could lead to a crash and denial of service. The highest threat from this vulnerability is to system availability.

Mitigation

Configuring the HTTP/2 feature via "H2Push off" will mitigate this vulnerability.