PT-2026-37040 · Apache+3 · Apache Http Server+3
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apache HTTP Server versions prior to 2.4.67
Description
A heap-based buffer overflow exists in the
mod proxy ajp module. If mod proxy ajp connects to a malicious AJP server, that server can send a crafted AJP message causing the system to write four attacker-controlled bytes beyond the end of a heap-based buffer, leading to memory corruption.Recommendations
Upgrade to version 2.4.67.
Exploit
Fix
DoS
RCE
Heap Based Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Http Server
Linuxmint
Rocky Linux
Ubuntu