Out-of-bounds write in Apache HTTP Server - CVE-2019-10081

 

Out-of-bounds write in Apache HTTP Server - CVE-2019-10081

Published: August 23, 2019 / Updated: August 23, 2019


Vulnerability identifier: #VU20373
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-10081
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform denial of service attack.

The vulnerability exists due to a boundary error when processing HTTP/2 requests within the mod_http2 module, configured with "H2PushResource". A remote attacker can send specially crafted HTTP/2 requests to the affected server and perform denial of service (DoS) attack.


Affected software

Apache HTTP Server
JBoss Core Services
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Slackware Linux
Opensuse
openEuler
jbcs-httpd24-brotli (Red Hat package)
jbcs-httpd24-apr (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
apache2 (Ubuntu package)
apache2 (Debian package)
jbcs-httpd24-httpd (Red Hat package)
apache2 (Alpine package)
httpd-filesystem
httpd-devel
httpd-debugsource
httpd-help
httpd-debuginfo
httpd
mod_ldap
httpd-tools
mod_md
mod_proxy_html
mod_session
mod_ssl
Dell Secure Connect Gateway
Maximo Application Suite - IoT Component

How to mitigate CVE-2019-10081

Install updates from vendor's website.

Apache HTTP Server - update to 2.4.41
jbcs-httpd24-brotli (Red Hat package) - addressed in versions 1.0.6-21.jbcs.el6, 1.0.6-21.jbcs.el7
jbcs-httpd24-apr (Red Hat package) - addressed in versions 1.6.3-86.jbcs.el6, 1.6.3-86.jbcs.el7
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.11.3-22.jbcs.el6, 1.11.3-22.jbcs.el7
apache2 (Ubuntu package) - addressed in versions 2.4.18-2ubuntu3.12, 2.4.18-2ubuntu3.13, 2.4.29-1ubuntu4.10, 2.4.29-1ubuntu4.11, 2.4.38-2ubuntu2.2, 2.4.38-2ubuntu2.3
apache2 (Debian package) - update to 2.4.25-3+deb9u8
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.37-52.jbcs.el6, 2.4.37-52.jbcs.el7
apache2 (Alpine package) - update to 2.4.41-r0
Dell Secure Connect Gateway - update to 5.12.00.10
httpd-filesystem - update to 2.4.34-18
httpd-devel - update to 2.4.34-18
httpd-debugsource - update to 2.4.34-18
httpd-help - update to 2.4.34-18
httpd-debuginfo - update to 2.4.34-18
httpd - update to 2.4.34-18
mod_ldap - update to 2.4.34-18
httpd-tools - update to 2.4.34-18
mod_md - update to 2.4.34-18
mod_proxy_html - update to 2.4.34-18
mod_session - update to 2.4.34-18
mod_ssl - update to 2.4.34-18
Maximo Application Suite - IoT Component - addressed in versions 8.7.20, 8.8.16, 9.0.6

External References

Related Security Bulletins