Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-13950

Опубликовано: 10 июн. 2021
Источник: debian
EPSS Средний

Описание

Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using both Content-Length and Transfer-Encoding headers, leading to a Denial of Service

Пакеты

ПакетСтатусВерсия исправленияРелизТип
apache2fixed2.4.48-1experimentalpackage
apache2fixed2.4.46-6package
apache2not-affectedbusterpackage
apache2not-affectedstretchpackage

Примечания

  • https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2020-13950

  • Fixed by: https://svn.apache.org/r1678771

  • Introduced by: https://svn.apache.org/r1656259

EPSS

Процентиль: 95%
0.1737
Средний

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 4 лет назад

Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using both Content-Length and Transfer-Encoding headers, leading to a Denial of Service

CVSS3: 7.5
redhat
около 4 лет назад

Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using both Content-Length and Transfer-Encoding headers, leading to a Denial of Service

CVSS3: 7.5
nvd
около 4 лет назад

Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using both Content-Length and Transfer-Encoding headers, leading to a Denial of Service

CVSS3: 7.5
msrc
около 4 лет назад

Описание отсутствует

rocky
около 3 лет назад

Low: httpd:2.4 security update

EPSS

Процентиль: 95%
0.1737
Средний