PT-2024-4676 · Apache+9 · Apache Http Server+9

Marc Stern

·

Published

2024-05-27

·

Updated

2025-08-13

·

CVE-2024-36387

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions: Apache HTTP Server (affected versions not specified)
Description: The issue is related to serving WebSocket protocol upgrades over a HTTP/2 connection, which could result in a Null Pointer dereference. This can lead to a crash of the server process and degrade performance. The vulnerability can be exploited by a remote attacker to cause a denial of service.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALSA-2024:8680
ALT-PU-2024-10005
ALT-PU-2024-10192
ALT-PU-2024-10221
ALT-PU-2024-10223
ALT-PU-2024-9738
ALT-PU-2024-9895
ALT-PU-2024-9963
ALT-PU-2024-9971
AZL-43089
AZL-43119
BDU:2024-05194
BIT-APACHE-2024-36387
CVE-2024-36387
DSA-5729-1
INFSA-2024_8680
MGASA-2024-0258
OESA-2024-1847
OESA-2024-1854
OPENSUSE-SU-2024:14116-1
OPENSUSE-SU-2024_2597-1
RHSA-2024:8680
RHSA-2024_8680
RHSA-2025:3452
RLSA-2024:8680
SUSE-SU-2024:2597-1
USN-6885-1
USN-6885-2
USN-6885-4
USN-6885-6

Affected Products

Alt Linux
Almalinux
Apache Http Server
Astra Linux
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu