Описание
In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.
A flaw was found in Apache's HTTP server (httpd) .The mod_proxy_ftp module may use uninitialized memory with proxying to a malicious FTP server. The highest threat from this vulnerability is to data confidentiality.
Отчет
This flaw is caused by use of an uninitialized memory variable. Practically this has no impact, but in some corner cases it is possible that the contents of this variable could be read by a remote process, causing loss of confidentiality as a result of this. There is no evidence of code execution.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | httpd | Out of support scope | ||
Red Hat Enterprise Linux 6 | httpd | Out of support scope | ||
Red Hat JBoss Enterprise Web Server 2 | httpd | Not affected | ||
Red Hat Software Collections | httpd24-httpd | Fix deferred | ||
JBoss Core Services on RHEL 6 | jbcs-httpd24-curl | Fixed | RHSA-2020:2644 | 22.06.2020 |
JBoss Core Services on RHEL 6 | jbcs-httpd24-httpd | Fixed | RHSA-2020:2644 | 22.06.2020 |
JBoss Core Services on RHEL 6 | jbcs-httpd24-mod_cluster-native | Fixed | RHSA-2020:2644 | 22.06.2020 |
JBoss Core Services on RHEL 6 | jbcs-httpd24-mod_http2 | Fixed | RHSA-2020:2644 | 22.06.2020 |
JBoss Core Services on RHEL 6 | jbcs-httpd24-mod_jk | Fixed | RHSA-2020:2644 | 22.06.2020 |
JBoss Core Services on RHEL 6 | jbcs-httpd24-mod_md | Fixed | RHSA-2020:2644 | 22.06.2020 |
Показывать по
Дополнительная информация
Статус:
EPSS
3.7 Low
CVSS3
Связанные уязвимости
In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.
In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.
In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitial ...
In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.
Уязвимость функции mod_proxy_ftp сервера приложений Apache Tomcat, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
EPSS
3.7 Low
CVSS3