Buffer overflow in Apache HTTP Server - CVE-2020-11984

 

Buffer overflow in Apache HTTP Server - CVE-2020-11984

Published: August 8, 2020 / Updated: July 3, 2025


Vulnerability identifier: #VU35713
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-11984
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in od_proxy_uwsgi module. A remote attacker can send a specially crafted request to the web server, trigger memory corruption and gain access to sensitive information or execute arbitrary code on the target system.


Affected software

Apache HTTP Server
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Opensuse
Ubuntu
openEuler
Fedora
apache2 (Alpine package)
httpd24-httpd (Red Hat package)
apache2 (Debian package)
libapache2-mod-uwsgi (Ubuntu package)
uwsgi (Ubuntu package)
libapache2-mod-proxy-uwsgi (Ubuntu package)
libapache2-mod-ruwsgi (Ubuntu package)
uwsgi-core (Ubuntu package)
apache2-bin (Ubuntu package)
apache2 (Ubuntu package)
mod_ssl
mod_session
mod_md
mod_ldap
mod_proxy_html
httpd
httpd-filesystem
httpd-help
httpd-debuginfo
httpd-debugsource
httpd-devel
httpd-tools
httpd24
Red Hat Software Collections
Oracle Communications Session Route Manager
Oracle Communications Element Manager
Oracle Communications Session Report Manager
Infrastructure Technology
Oracle ZFS Storage Appliance Kit
Oracle Enterprise Manager Ops Center
Instantis EnterpriseTrack
Watson Studio on Cloud Pak for Data
Maximo Application Suite - IoT Component

How to mitigate CVE-2020-11984

Install updates from vendor's website.

Apache HTTP Server - update to 2.4.44
httpd24-httpd (Red Hat package) - update to 2.4.34-22.el7
apache2 (Debian package) - update to 2.4.38-3+deb10u4
apache2 (Alpine package) - update to 1.7-0ubuntu1
libapache2-mod-uwsgi (Ubuntu package) - update to 2.0.15-10.2ubuntu2.2
uwsgi (Ubuntu package) - update to 2.0.15-10.2ubuntu2.2
libapache2-mod-proxy-uwsgi (Ubuntu package) - addressed in versions 2.0.15-10.2ubuntu2.2, 2.4.41-4ubuntu3.1
libapache2-mod-ruwsgi (Ubuntu package) - update to 2.0.15-10.2ubuntu2.2
uwsgi-core (Ubuntu package) - update to 2.0.15-10.2ubuntu2.2
apache2-bin (Ubuntu package) - addressed in versions 2.4.18-2ubuntu3.17, 2.4.29-1ubuntu4.14, 2.4.41-4ubuntu3.12
apache2 (Ubuntu package) - addressed in versions 2.4.18-2ubuntu3.17, 2.4.29-1ubuntu4.14, 2.4.41-4ubuntu3.19
mod_ssl - update to 2.4.43-3
mod_session - update to 2.4.43-3
mod_md - update to 2.4.43-3
mod_ldap - update to 2.4.43-3
mod_proxy_html - update to 2.4.43-3
httpd - update to 2.4.43-3
httpd-filesystem - update to 2.4.43-3
httpd-help - update to 2.4.43-3
httpd-debuginfo - update to 2.4.43-3
httpd-debugsource - update to 2.4.43-3
httpd-devel - update to 2.4.43-3
httpd-tools - update to 2.4.43-3
httpd - addressed in versions 2.4.46-1.fc31, 2.4.46-1.fc32
httpd24 - update to 2.4.46-1.90
Watson Studio on Cloud Pak for Data - addressed in versions 4.8.7, 5.1.0
Maximo Application Suite - IoT Component - addressed in versions 8.7.20, 8.8.16, 9.0.6

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins