PT-2023-20329 · Apache · Apache Httpd
Félix Arreola Rodríguez
·
Published
2023-02-23
·
Updated
2023-05-16
·
CVE-2023-25824
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Mod gnutls versions 0.9.0 through 0.12.0
Description
Mod gnutls is a TLS module for Apache HTTPD based on GnuTLS. It did not properly fail blocking read operations on TLS connections when the transport hit timeouts, entering an endless loop and consuming CPU resources. This could be exploited for denial of service attacks. If trace level logging was enabled, it would also produce an excessive amount of log output during the loop, consuming disk space.
Recommendations
Update to version 0.12.1 to fix the issue.
For users who cannot update, apply the errno fix detailed in the security advisory.
Exploit
Fix
Infinite Loop
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Httpd