PT-2019-3892 · Apache+7 · Apache Http Server+7

Published

2019-04-03

·

Updated

2024-06-15

·

CVE-2019-10097

CVSS v2.0

8.5

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.4.32 through 2.4.39
Description The issue is related to a stack buffer overflow or NULL pointer deference in the mod remoteip module of the Apache HTTP Server. This can be triggered by a specially crafted PROXY header from a trusted intermediary proxy server using the "PROXY" protocol. The vulnerability can only be exploited by a trusted proxy, not by untrusted HTTP clients.
Recommendations For Apache HTTP Server versions 2.4.32 through 2.4.39, consider disabling the mod remoteip module until a patch is available to prevent potential exploitation. Restrict access to the PROXY protocol to minimize the risk of exploitation. Avoid using the PROXY header in the affected module until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

NULL Pointer Dereference

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2020:4751
ALT-PU-2019-1580
BDU:2019-04285
CESA-2020_4751
CVE-2019-10097
DSA-4509-1
DSA-4509-2
MGASA-2019-0407
OPENSUSE-SU-2019:2051-1
OPENSUSE-SU-2019_2051-1
OPENSUSE-SU-2024:10623-1
RHSA-2019:4126
RHSA-2020:1337
RHSA-2020:4751
RHSA-2020_4751
RLSA-2020:4751
SUSE-SU-2019:2237-1
USN-4113-1
USN-4113-2

Affected Products

Alt Linux
Almalinux
Apache Http Server
Centos
Red Hat
Rocky Linux
Suse
Ubuntu