PT-2019-3892 · Apache+7 · Apache Http Server+7
Published
2019-04-03
·
Updated
2024-06-15
·
CVE-2019-10097
CVSS v2.0
8.5
High
| Vector | AV:N/AC:M/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apache HTTP Server versions 2.4.32 through 2.4.39
Description
The issue is related to a stack buffer overflow or NULL pointer deference in the mod remoteip module of the Apache HTTP Server. This can be triggered by a specially crafted PROXY header from a trusted intermediary proxy server using the "PROXY" protocol. The vulnerability can only be exploited by a trusted proxy, not by untrusted HTTP clients.
Recommendations
For Apache HTTP Server versions 2.4.32 through 2.4.39, consider disabling the mod remoteip module until a patch is available to prevent potential exploitation. Restrict access to the PROXY protocol to minimize the risk of exploitation. Avoid using the PROXY header in the affected module until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Buffer Overflow
NULL Pointer Dereference
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Apache Http Server
Centos
Red Hat
Rocky Linux
Suse
Ubuntu