PT-2020-6242 · Apache+9 · Apache Http Server+9
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Apache HTTP Server versions 2.4.0 through 2.4.46
Description
The issue is caused by a stack overflow in the
mod auth digest function of the Apache HTTP Server. This can be triggered by a specially crafted Digest nonce. Although there are no reports of this overflow being exploitable, certain compiler and/or compilation options might make it possible, with limited consequences due to the size and value of the overflow.Recommendations
For Apache HTTP Server versions 2.4.0 through 2.4.46, consider updating to a version where this issue is fixed, as the current version may be vulnerable to a stack overflow in the
mod auth digest function.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.DoS
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Apache Http Server
Astra Linux
Centos
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu