Infinite loop in Apache HTTP Server - CVE-2019-0190

 

Infinite loop in Apache HTTP Server - CVE-2019-0190

Published: January 23, 2019 / Updated: January 24, 2019


Vulnerability identifier: #VU17179
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-0190
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists in the mod_ssl module due to improper handling of renegotiation attempts when OpenSSL 1.1.1 or later is used. A remote attacker can send a specially crafted request that submits malicious input, trigger mod_ssl loop and cause the service to crash.

Affected software

Apache HTTP Server
Arch Linux
Amazon Linux AMI
Gentoo Linux
Slackware Linux
apache2 (Alpine package)
Oracle Retail Xstore Point of Service
Maximo Application Suite - IoT Component
Instantis EnterpriseTrack
Oracle Essbase

How to mitigate CVE-2019-0190

Update to version 2.4.38.

Apache HTTP Server - update to 2.4.38
apache2 (Alpine package) - update to 2.4.38-r0
Maximo Application Suite - IoT Component - addressed in versions 8.7.20, 8.8.16, 9.0.6

External References

Related Security Bulletins