Out-of-bounds write in Apache HTTP Server - CVE-2019-10081
Published: August 23, 2019 / Updated: August 23, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform denial of service attack.
The vulnerability exists due to a boundary error when processing HTTP/2 requests within the mod_http2 module, configured with "H2PushResource". A remote attacker can send specially crafted HTTP/2 requests to the affected server and perform denial of service (DoS) attack.
Affected software
JBoss Core Services
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Slackware Linux
Opensuse
openEuler
jbcs-httpd24-brotli (Red Hat package)
jbcs-httpd24-apr (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
apache2 (Ubuntu package)
apache2 (Debian package)
jbcs-httpd24-httpd (Red Hat package)
apache2 (Alpine package)
httpd-filesystem
httpd-devel
httpd-debugsource
httpd-help
httpd-debuginfo
httpd
mod_ldap
httpd-tools
mod_md
mod_proxy_html
mod_session
mod_ssl
Dell Secure Connect Gateway
Maximo Application Suite - IoT Component
How to mitigate CVE-2019-10081
jbcs-httpd24-brotli (Red Hat package) - addressed in versions 1.0.6-21.jbcs.el6, 1.0.6-21.jbcs.el7
jbcs-httpd24-apr (Red Hat package) - addressed in versions 1.6.3-86.jbcs.el6, 1.6.3-86.jbcs.el7
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.11.3-22.jbcs.el6, 1.11.3-22.jbcs.el7
apache2 (Ubuntu package) - addressed in versions 2.4.18-2ubuntu3.12, 2.4.18-2ubuntu3.13, 2.4.29-1ubuntu4.10, 2.4.29-1ubuntu4.11, 2.4.38-2ubuntu2.2, 2.4.38-2ubuntu2.3
apache2 (Debian package) - update to 2.4.25-3+deb9u8
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.37-52.jbcs.el6, 2.4.37-52.jbcs.el7
apache2 (Alpine package) - update to 2.4.41-r0
Dell Secure Connect Gateway - update to 5.12.00.10
httpd-filesystem - update to 2.4.34-18
httpd-devel - update to 2.4.34-18
httpd-debugsource - update to 2.4.34-18
httpd-help - update to 2.4.34-18
httpd-debuginfo - update to 2.4.34-18
httpd - update to 2.4.34-18
mod_ldap - update to 2.4.34-18
httpd-tools - update to 2.4.34-18
mod_md - update to 2.4.34-18
mod_proxy_html - update to 2.4.34-18
mod_session - update to 2.4.34-18
mod_ssl - update to 2.4.34-18
Maximo Application Suite - IoT Component - addressed in versions 8.7.20, 8.8.16, 9.0.6
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache HTTP Server
- Debian update for apache2
- Ubuntu update for Apache HTTP Server
- OpenSUSE Linux update for apache2
- Gentoo update for Apache
- Ubuntu regression update for Apache HTTP Server
- Amazon Linux AMI update for httpd24
- Slackware Linux update for httpd
- Red Hat JBoss Core Services update for Apache HTTP Server
- Out-of-bounds write in apache2 (Alpine package)
- Red Hat Enterprise Linux 8 update for the httpd:2.4 module
- Multiple vulnerabilities in DELL Secure Connect Gateway Security
- openEuler 20.03 LTS update for httpd
- Multiple vulnerabilities in IBM Maximo Application Suite - IoT Component