Infinite loop in Apache HTTP Server - CVE-2019-0190
Published: January 23, 2019 / Updated: January 24, 2019
Vulnerability identifier: #VU17179
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-0190
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists in the mod_ssl module due to improper handling of renegotiation attempts when OpenSSL 1.1.1 or later is used. A remote attacker can send a specially crafted request that submits malicious input, trigger mod_ssl loop and cause the service to crash.
The weakness exists in the mod_ssl module due to improper handling of renegotiation attempts when OpenSSL 1.1.1 or later is used. A remote attacker can send a specially crafted request that submits malicious input, trigger mod_ssl loop and cause the service to crash.
Affected software
Apache HTTP Server
Arch Linux
Amazon Linux AMI
Gentoo Linux
Slackware Linux
apache2 (Alpine package)
Oracle Retail Xstore Point of Service
Maximo Application Suite - IoT Component
Instantis EnterpriseTrack
Oracle Essbase
Arch Linux
Amazon Linux AMI
Gentoo Linux
Slackware Linux
apache2 (Alpine package)
Oracle Retail Xstore Point of Service
Maximo Application Suite - IoT Component
Instantis EnterpriseTrack
Oracle Essbase
How to mitigate CVE-2019-0190
Update to version 2.4.38.
Apache HTTP Server - update to 2.4.38
apache2 (Alpine package) - update to 2.4.38-r0
Maximo Application Suite - IoT Component - addressed in versions 8.7.20, 8.8.16, 9.0.6
apache2 (Alpine package) - update to 2.4.38-r0
Maximo Application Suite - IoT Component - addressed in versions 8.7.20, 8.8.16, 9.0.6
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache HTTP Server
- Slackware Linux update for httpd
- Arch Linux update for apache
- Amazon Linux AMI update for httpd24
- Gentoo update for Apache
- Infinite loop in apache2 (Alpine package)
- Multiple vulnerabilities in Essbase
- Multiple vulnerabilities in IBM Maximo Application Suite - IoT Component
- Multiple vulnerabilities in Instantis EnterpriseTrack
- Multiple vulnerabilities in Oracle Retail Xstore Point of Service