PT-2020-6242 · Apache+9 · Apache Http Server+9

·

CVE-2020-35452

·

Published

2020-11-11

·

Updated

2024-03-06

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.4.0 through 2.4.46
Description The issue is caused by a stack overflow in the mod auth digest function of the Apache HTTP Server. This can be triggered by a specially crafted Digest nonce. Although there are no reports of this overflow being exploitable, certain compiler and/or compilation options might make it possible, with limited consequences due to the size and value of the overflow.
Recommendations For Apache HTTP Server versions 2.4.0 through 2.4.46, consider updating to a version where this issue is fixed, as the current version may be vulnerable to a stack overflow in the mod auth digest function. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:1915
ALT-PU-2021-1838
ALT-PU-2021-2035
ALT-PU-2021-2339
AZL-6475
BDU:2021-03679
BIT-APACHE-2020-35452
CESA-2022_1915
CVE-2020-35452
DLA-2706-1
DSA-4937-1
MGASA-2021-0265
OESA-2021-1246
OPENSUSE-SU-2021:0908-1
OPENSUSE-SU-2021:2127-1
OPENSUSE-SU-2021_0908-1
OPENSUSE-SU-2021_2127-1
RHSA-2021:4614
RHSA-2022:1915
RHSA-2022_1915
RLSA-2022:1915
SUSE-SU-2021:14749-1
SUSE-SU-2021:2004-1
SUSE-SU-2021:2006-1
SUSE-SU-2021:2127-1
SUSE-SU-2021_14749-1
SUSE-SU-2021_2006-1
USN-4994-1
USN-4994-2

Affected Products

Alt Linux
Almalinux
Apache Http Server
Astra Linux
Centos
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu