Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-41524

Опубликовано: 05 окт. 2021
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The vulnerability was recently introduced in version 2.4.49. No exploit is known to the project.

Отчет

This issue only affects Apache HTTP Server 2.4.49 and Red Hat JBoss Core Services Apache HTTP Server 2.4.37 SP9, earlier versions are not affected. Therefore this issue does not affect the other versions of Apache HTTP Server shipped with Red Hat products.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6httpdNot affected
Red Hat Enterprise Linux 7httpdNot affected
Red Hat Enterprise Linux 8httpd:2.4/httpdNot affected
Red Hat Enterprise Linux 9httpdNot affected
Red Hat JBoss Enterprise Application Platform 6httpdOut of support scope
Red Hat Software Collectionshttpd24-httpdNot affected
JBoss Core Services for RHEL 8jbcs-httpd24-httpdFixedRHSA-2022:714326.10.2022
JBoss Core Services on RHEL 7jbcs-httpd24-httpdFixedRHSA-2022:714326.10.2022
Text-Only JBCSjbcs-httpd24-httpdFixedRHSA-2022:714426.10.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2010934httpd: NULL pointer dereference via crafted request during HTTP/2 request processing

EPSS

Процентиль: 91%
0.07103
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The vulnerability was recently introduced in version 2.4.49. No exploit is known to the project.

CVSS3: 7.5
nvd
больше 4 лет назад

While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The vulnerability was recently introduced in version 2.4.49. No exploit is known to the project.

CVSS3: 7.5
msrc
больше 4 лет назад

null pointer dereference in h2 fuzzing

CVSS3: 7.5
debian
больше 4 лет назад

While fuzzing the 2.4.49 httpd, a new null pointer dereference was det ...

CVSS3: 7.5
github
больше 3 лет назад

While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The vulnerability was recently introduced in version 2.4.49. No exploit is known to the project.

EPSS

Процентиль: 91%
0.07103
Низкий

7.5 High

CVSS3