Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-10081

Опубликовано: 14 авг. 2019
Источник: redhat
CVSS3: 5.3
EPSS Средний

Описание

HTTP/2 (2.4.20 through 2.4.39) very early pushes, for example configured with "H2PushResource", could lead to an overwrite of memory in the pushing request's pool, leading to crashes. The memory copied is that of the configured push link header values, not data supplied by the client.

A vulnerability was found in Apache httpd, in mod_http2. Under certain circumstances, HTTP/2 early pushes could lead to memory corruption, causing a server to crash.

Меры по смягчению последствий

This flaw is only exploitable if Apache httpd is configured to respond to HTTP/2 requests, which is done by including "h2" or "h2c" in the "Protocols" list in a configuration file. The following command can be used to search for possible vulnerable configurations: grep -R '^\sProtocols>.<h2>' /etc/httpd/ See https://httpd.apache.org/docs/2.4/mod/mod_http2.html

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5httpdNot affected
Red Hat Enterprise Linux 6httpdNot affected
Red Hat Enterprise Linux 7httpdNot affected
Red Hat JBoss Enterprise Web Server 2httpdOut of support scope
Red Hat JBoss Enterprise Web Server 2httpd22Out of support scope
Red Hat JBoss Web Server 3httpd24Out of support scope
Red Hat Software Collectionshttpd24-httpdWill not fix
JBoss Core Services Apache HTTP Server 2.4.37 SP2httpdFixedRHSA-2020:133606.04.2020
JBoss Core Services on RHEL 6jbcs-httpd24-aprFixedRHSA-2020:133706.04.2020
JBoss Core Services on RHEL 6jbcs-httpd24-brotliFixedRHSA-2020:133706.04.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1743966httpd: memory corruption on early pushes

EPSS

Процентиль: 96%
0.26679
Средний

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 6 лет назад

HTTP/2 (2.4.20 through 2.4.39) very early pushes, for example configured with "H2PushResource", could lead to an overwrite of memory in the pushing request's pool, leading to crashes. The memory copied is that of the configured push link header values, not data supplied by the client.

CVSS3: 7.5
nvd
почти 6 лет назад

HTTP/2 (2.4.20 through 2.4.39) very early pushes, for example configured with "H2PushResource", could lead to an overwrite of memory in the pushing request's pool, leading to crashes. The memory copied is that of the configured push link header values, not data supplied by the client.

CVSS3: 7.5
debian
почти 6 лет назад

HTTP/2 (2.4.20 through 2.4.39) very early pushes, for example configur ...

CVSS3: 7.5
github
около 3 лет назад

HTTP/2 (2.4.20 through 2.4.39) very early pushes, for example configured with "H2PushResource", could lead to an overwrite of memory in the pushing request's pool, leading to crashes. The memory copied is that of the configured push link header values, not data supplied by the client.

CVSS3: 7.5
fstec
почти 6 лет назад

Уязвимость реализации сетевого протокола HTTP/2 веб-сервера Apache HTTP Server, связанная с чтением за границами буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 96%
0.26679
Средний

5.3 Medium

CVSS3

Уязвимость CVE-2019-10081