Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-38477

Опубликовано: 01 июл. 2024
Источник: redhat
CVSS3: 7.5

Описание

null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

A flaw was found in the mod_proxy module of httpd. A NULL pointer dereference can be triggered when processing a specially crafted HTTP request, causing the httpd server to crash, and resulting in a denial of service.

Отчет

As this flaw allows a remote attacker to cause a denial of service, it has been rated with an important severity. This flaw only affects configurations with mod_proxy loaded and being used. This module can be disabled via the configuration file if its functionality is not being used.

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10httpdNot affected
Red Hat Enterprise Linux 6httpdNot affected
Red Hat JBoss Core ServiceshttpdAffected
JBoss Core Services for RHEL 8jbcs-httpd24-httpdFixedRHSA-2024:523913.08.2024
JBoss Core Services for RHEL 8jbcs-httpd24-mod_http2FixedRHSA-2024:523913.08.2024
JBoss Core Services for RHEL 8jbcs-httpd24-mod_jkFixedRHSA-2024:523913.08.2024
JBoss Core Services for RHEL 8jbcs-httpd24-mod_mdFixedRHSA-2024:523913.08.2024
JBoss Core Services for RHEL 8jbcs-httpd24-mod_proxy_clusterFixedRHSA-2024:523913.08.2024
JBoss Core Services for RHEL 8jbcs-httpd24-mod_securityFixedRHSA-2024:523913.08.2024
JBoss Core Services on RHEL 7jbcs-httpd24-httpdFixedRHSA-2024:523913.08.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2295016httpd: NULL pointer dereference in mod_proxy

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
12 месяцев назад

null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

CVSS3: 7.5
nvd
12 месяцев назад

null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

CVSS3: 7.5
debian
12 месяцев назад

null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and ...

CVSS3: 7.5
github
12 месяцев назад

null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

CVSS3: 7.5
fstec
около 1 года назад

Уязвимость модуля mod_proxy веб-сервера Apache HTTP Server, позволяющая нарушителю вызвать отказ в обслуживании

7.5 High

CVSS3