Use-after-free in Apache HTTP Server - CVE-2019-10082

 

Use-after-free in Apache HTTP Server - CVE-2019-10082

Published: August 23, 2019


Vulnerability identifier: #VU20386
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-10082
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform denial of service (DoS) attack.

The vulnerability exists due to a use-after-free error within the mod_http2 when handling connection shutdown. A remote attacker can send specially crafted requests to the affected server and make the mod_http2 to read memory that was already freed.



Affected software

Apache HTTP Server
JBoss Core Services
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Slackware Linux
Opensuse
openEuler
jbcs-httpd24-brotli (Red Hat package)
jbcs-httpd24-apr (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
apache2 (Ubuntu package)
apache2 (Debian package)
jbcs-httpd24-httpd (Red Hat package)
apache2 (Alpine package)
mod_proxy_html
httpd-tools
httpd-help
httpd-filesystem
httpd-devel
httpd-debugsource
httpd-debuginfo
httpd
mod_ldap
mod_md
mod_session
mod_ssl
Dell Secure Connect Gateway
Oracle HTTP Server
Oracle Retail Xstore Point of Service
Watson Studio on Cloud Pak for Data
Maximo Application Suite - IoT Component
Oracle Communications Element Manager
Instantis EnterpriseTrack

How to mitigate CVE-2019-10082

Install updates from vendor's website.

Apache HTTP Server - update to 2.4.41
jbcs-httpd24-brotli (Red Hat package) - addressed in versions 1.0.6-21.jbcs.el6, 1.0.6-21.jbcs.el7
jbcs-httpd24-apr (Red Hat package) - addressed in versions 1.6.3-86.jbcs.el6, 1.6.3-86.jbcs.el7
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.11.3-22.jbcs.el6, 1.11.3-22.jbcs.el7
apache2 (Ubuntu package) - addressed in versions 2.4.18-2ubuntu3.12, 2.4.18-2ubuntu3.13, 2.4.29-1ubuntu4.10, 2.4.29-1ubuntu4.11, 2.4.38-2ubuntu2.2, 2.4.38-2ubuntu2.3
apache2 (Debian package) - update to 2.4.25-3+deb9u8
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.37-52.jbcs.el6, 2.4.37-52.jbcs.el7
apache2 (Alpine package) - update to 2.4.41-r0
Dell Secure Connect Gateway - update to 5.12.00.10
mod_proxy_html - addressed in versions 2.4.34-17, 2.4.34-18
httpd-tools - addressed in versions 2.4.34-17, 2.4.34-18
httpd-help - addressed in versions 2.4.34-17, 2.4.34-18
httpd-filesystem - addressed in versions 2.4.34-17, 2.4.34-18
httpd-devel - addressed in versions 2.4.34-17, 2.4.34-18
httpd-debugsource - addressed in versions 2.4.34-17, 2.4.34-18
httpd-debuginfo - addressed in versions 2.4.34-17, 2.4.34-18
httpd - addressed in versions 2.4.34-17, 2.4.34-18
mod_ldap - addressed in versions 2.4.34-17, 2.4.34-18
mod_md - addressed in versions 2.4.34-17, 2.4.34-18
mod_session - addressed in versions 2.4.34-17, 2.4.34-18
mod_ssl - addressed in versions 2.4.34-17, 2.4.34-18
Watson Studio on Cloud Pak for Data - addressed in versions 4.8.7, 5.1.0
Maximo Application Suite - IoT Component - addressed in versions 8.7.20, 8.8.16, 9.0.6

External References

Related Security Bulletins