Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-24795

Опубликовано: 04 апр. 2024
Источник: debian
EPSS Низкий

Описание

HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, which fixes this issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
apache2fixed2.4.59-1package
uwsgiunfixedpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2024/04/04/5

  • https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2024-24795

  • https://github.com/apache/httpd/commit/a29723ce1af75eed0813c3717d3f6dee9b405ca8

  • Fix will trigger a regression at least in fossil see https://bz.apache.org/bugzilla/show_bug.cgi?id=68905

  • https://fossil-scm.org/home/info/a8e33fb161f45b65 (version-2.24)

  • https://fossil-scm.org/home/info/71919ad1b542832c (version-2.24)

  • https://fossil-scm.org/home/info/f4ffefe708793b03 (version-2.24)

  • https://fossil-scm.org/home/info/5f47bb59a7846aeb (version-2.24)

  • uwsgi since 2.0.15-11 drops building the libapache2-mod-proxy-uwsgi{,-dbg}

  • packages which are provided by src:apache2 itself.

  • https://github.com/unbit/uwsgi/issues/2635

EPSS

Процентиль: 47%
0.00238
Низкий

Связанные уязвимости

CVSS3: 6.3
ubuntu
около 1 года назад

HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, which fixes this issue.

CVSS3: 4
redhat
около 1 года назад

HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, which fixes this issue.

CVSS3: 6.3
nvd
около 1 года назад

HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, which fixes this issue.

CVSS3: 6.3
msrc
8 месяцев назад

Описание отсутствует

suse-cvrf
8 месяцев назад

Security update for uwsgi

EPSS

Процентиль: 47%
0.00238
Низкий