Описание
Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server.
This issue affects Apache HTTP Server: through 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.
A flaw was found in the mod_proxy_ajp module of httpd. When processing AJP (Apache JServ Protocol) messages, the server fails to properly check if a string is null-terminated before attempting to read it, allowing an attacker or a malformed request to cause a heap-based buffer over-read. This issue potentially leads to memory disclosure and a denial of service.
Отчет
To exploit this issue, the Apache HTTP Server must be configured to connect to an untrusted or compromised AJP backend server, limiting its exposure. Due to this reason, this flaw has been rated with a moderate severity. This flaw only affects configurations with mod_proxy_ajp loaded and being used. This module can be disabled via the configuration file if its functionality is not being used.
Меры по смягчению последствий
Disabling mod_proxy_ajp and restarting httpd will mitigate this flaw.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | httpd | Affected | ||
| Red Hat Enterprise Linux 7 | httpd | Affected | ||
| JBoss Core Services for RHEL 8 | jbcs-httpd24-httpd | Fixed | RHSA-2026:27200 | 22.06.2026 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-httpd | Fixed | RHSA-2026:27200 | 22.06.2026 |
| Red Hat Enterprise Linux 10 | httpd | Fixed | RHSA-2026:21433 | 27.05.2026 |
| Red Hat Enterprise Linux 8 | httpd | Fixed | RHSA-2026:22140 | 01.06.2026 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | httpd | Fixed | RHSA-2026:36846 | 08.07.2026 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | httpd | Fixed | RHSA-2026:36846 | 08.07.2026 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | httpd | Fixed | RHSA-2026:36831 | 08.07.2026 |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | httpd | Fixed | RHSA-2026:36831 | 08.07.2026 |
Показывать по
Дополнительная информация
Статус:
8.2 High
CVSS3
Связанные уязвимости
Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
Apache HTTP Server: mod_proxy_ajp: Heap Buffer Over-Read Due to Missing Null-Termination Check (ajp_msg_get_string)
Improper Null Termination, Out-of-bounds Read vulnerability in Apache ...
Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
8.2 High
CVSS3