Buffer overflow in Apache HTTP Server - CVE-2020-11984
Published: August 8, 2020 / Updated: July 3, 2025
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in od_proxy_uwsgi module. A remote attacker can send a specially crafted request to the web server, trigger memory corruption and gain access to sensitive information or execute arbitrary code on the target system.
Affected software
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Opensuse
Ubuntu
openEuler
Fedora
apache2 (Alpine package)
httpd24-httpd (Red Hat package)
apache2 (Debian package)
libapache2-mod-uwsgi (Ubuntu package)
uwsgi (Ubuntu package)
libapache2-mod-proxy-uwsgi (Ubuntu package)
libapache2-mod-ruwsgi (Ubuntu package)
uwsgi-core (Ubuntu package)
apache2-bin (Ubuntu package)
apache2 (Ubuntu package)
mod_ssl
mod_session
mod_md
mod_ldap
mod_proxy_html
httpd
httpd-filesystem
httpd-help
httpd-debuginfo
httpd-debugsource
httpd-devel
httpd-tools
httpd24
Red Hat Software Collections
Oracle Communications Session Route Manager
Oracle Communications Element Manager
Oracle Communications Session Report Manager
Infrastructure Technology
Oracle ZFS Storage Appliance Kit
Oracle Enterprise Manager Ops Center
Instantis EnterpriseTrack
Watson Studio on Cloud Pak for Data
Maximo Application Suite - IoT Component
How to mitigate CVE-2020-11984
httpd24-httpd (Red Hat package) - update to 2.4.34-22.el7
apache2 (Debian package) - update to 2.4.38-3+deb10u4
apache2 (Alpine package) - update to 1.7-0ubuntu1
libapache2-mod-uwsgi (Ubuntu package) - update to 2.0.15-10.2ubuntu2.2
uwsgi (Ubuntu package) - update to 2.0.15-10.2ubuntu2.2
libapache2-mod-proxy-uwsgi (Ubuntu package) - addressed in versions 2.0.15-10.2ubuntu2.2, 2.4.41-4ubuntu3.1
libapache2-mod-ruwsgi (Ubuntu package) - update to 2.0.15-10.2ubuntu2.2
uwsgi-core (Ubuntu package) - update to 2.0.15-10.2ubuntu2.2
apache2-bin (Ubuntu package) - addressed in versions 2.4.18-2ubuntu3.17, 2.4.29-1ubuntu4.14, 2.4.41-4ubuntu3.12
apache2 (Ubuntu package) - addressed in versions 2.4.18-2ubuntu3.17, 2.4.29-1ubuntu4.14, 2.4.41-4ubuntu3.19
mod_ssl - update to 2.4.43-3
mod_session - update to 2.4.43-3
mod_md - update to 2.4.43-3
mod_ldap - update to 2.4.43-3
mod_proxy_html - update to 2.4.43-3
httpd - update to 2.4.43-3
httpd-filesystem - update to 2.4.43-3
httpd-help - update to 2.4.43-3
httpd-debuginfo - update to 2.4.43-3
httpd-debugsource - update to 2.4.43-3
httpd-devel - update to 2.4.43-3
httpd-tools - update to 2.4.43-3
httpd - addressed in versions 2.4.46-1.fc31, 2.4.46-1.fc32
httpd24 - update to 2.4.46-1.90
Watson Studio on Cloud Pak for Data - addressed in versions 4.8.7, 5.1.0
Maximo Application Suite - IoT Component - addressed in versions 8.7.20, 8.8.16, 9.0.6
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache HTTP Server
- Gentoo update for Apache
- OpenSUSE Linux update for apache2
- OpenSUSE Linux update for apache2
- Amazon Linux AMI update for httpd24
- Debian update for apache2
- Buffer overflow in apache2 (Alpine package)
- Multiple vulnerabilities in Oracle Communications Session Route Manager
- Multiple vulnerabilities in Oracle Communications Session Report Manager
- Multiple vulnerabilities in Oracle Communications Element Manager
- Multiple vulnerabilities in Instantis EnterpriseTrack
- Red Hat Software Collections 1 for RHEL 7.7 update for Apache HTTP Server
- Multiple vulnerabilities in Oracle Enterprise Manager Ops Center
- Multiple vulnerabilities in Hyperion Infrastructure Technology
- Multiple vulnerabilities in Oracle ZFS Storage Appliance Kit
- Red Hat Enterprise Linux 8 update for the httpd:2.4 module
- Ubuntu update for uwsgi
- openEuler 20.03 LTS update for httpd
- Amazon Linux AMI update for httpd24
- Amazon Linux AMI update for httpd24
- Multiple vulnerabilities in IBM Watson Studio on Cloud Pak for Data
- Multiple vulnerabilities in IBM Maximo Application Suite - IoT Component
- Ubuntu update for apache2
- Fedora 32 update for httpd
- Fedora 31 update for httpd