Описание
A specially crafted request could have crashed the Apache HTTP Server prior to version 2.4.30, due to an out of bound access after a size limit is reached by reading the HTTP header. This vulnerability is considered very hard if not impossible to trigger in non-debug mode (both log and build level), so it is classified as low risk for common server usage.
Релиз | Статус | Примечание |
---|---|---|
artful | released | 2.4.27-2ubuntu4.1 |
bionic | released | 2.4.29-1ubuntu4.1 |
cosmic | released | 2.4.29-1ubuntu4.1 |
devel | released | 2.4.29-1ubuntu4.1 |
esm-infra-legacy/trusty | not-affected | 2.4.7-1ubuntu4.20 |
esm-infra/bionic | not-affected | 2.4.29-1ubuntu4.1 |
esm-infra/xenial | not-affected | 2.4.18-2ubuntu3.8 |
precise/esm | not-affected | 2.2.22-1ubuntu1.15 |
trusty | released | 2.4.7-1ubuntu4.20 |
trusty/esm | not-affected | 2.4.7-1ubuntu4.20 |
Показывать по
Ссылки на источники
EPSS
4.3 Medium
CVSS2
5.9 Medium
CVSS3
Связанные уязвимости
A specially crafted request could have crashed the Apache HTTP Server prior to version 2.4.30, due to an out of bound access after a size limit is reached by reading the HTTP header. This vulnerability is considered very hard if not impossible to trigger in non-debug mode (both log and build level), so it is classified as low risk for common server usage.
A specially crafted request could have crashed the Apache HTTP Server prior to version 2.4.30, due to an out of bound access after a size limit is reached by reading the HTTP header. This vulnerability is considered very hard if not impossible to trigger in non-debug mode (both log and build level), so it is classified as low risk for common server usage.
A specially crafted request could have crashed the Apache HTTP Server ...
A specially crafted request could have crashed the Apache HTTP Server prior to version 2.4.30, due to an out of bound access after a size limit is reached by reading the HTTP header. This vulnerability is considered very hard if not impossible to trigger in non-debug mode (both log and build level), so it is classified as low risk for common server usage.
Уязвимость веб-сервера Apache HTTP Server, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
4.3 Medium
CVSS2
5.9 Medium
CVSS3