Resource management error in Apache HTTP Server - CVE-2020-11993
Published: August 8, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of internal resources within the application while processing HTTP/2 requests with enabled trace/debug for HTTP/2 connections. A remote attacker can send specially crafted HTTP/2 requests to Apache HTTP Server and force it to make logging statements on wrong connection for certain traffic edge patterns. This results in concurrent use of memory pools for separate connections and triggers denial of service condition.
Affected software
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Opensuse
Ubuntu
openEuler
Fedora
apache2 (Alpine package)
httpd24-httpd (Red Hat package)
apache2 (Debian package)
mod_http2
apache2 (Ubuntu package)
apache2-bin (Ubuntu package)
libapache2-mod-proxy-uwsgi (Ubuntu package)
mod_ldap
mod_md
mod_proxy_html
mod_session
mod_ssl
httpd-tools
httpd-devel
httpd-debugsource
httpd-debuginfo
httpd-help
httpd-filesystem
httpd
httpd24
Red Hat Software Collections
Dell Secure Connect Gateway
Maximo Application Suite - IoT Component
How to mitigate CVE-2020-11993
httpd24-httpd (Red Hat package) - update to 2.4.34-22.el7
apache2 (Debian package) - update to 2.4.38-3+deb10u4
Dell Secure Connect Gateway - update to 5.12.00.10
apache2 (Alpine package) - update to 1.7-0ubuntu1
mod_http2 - addressed in versions 1.15.14-1.fc31, 1.15.14-1.fc32
apache2 (Ubuntu package) - addressed in versions 2.4.18-2ubuntu3.17, 2.4.29-1ubuntu4.14, 2.4.41-4ubuntu3.19
apache2-bin (Ubuntu package) - addressed in versions 2.4.18-2ubuntu3.17, 2.4.29-1ubuntu4.14, 2.4.41-4ubuntu3.12
libapache2-mod-proxy-uwsgi (Ubuntu package) - update to 2.4.41-4ubuntu3.1
mod_ldap - update to 2.4.43-3
mod_md - update to 2.4.43-3
mod_proxy_html - update to 2.4.43-3
mod_session - update to 2.4.43-3
mod_ssl - update to 2.4.43-3
httpd-tools - update to 2.4.43-3
httpd-devel - update to 2.4.43-3
httpd-debugsource - update to 2.4.43-3
httpd-debuginfo - update to 2.4.43-3
httpd-help - update to 2.4.43-3
httpd-filesystem - update to 2.4.43-3
httpd - update to 2.4.43-3
httpd24 - update to 2.4.46-1.90
Maximo Application Suite - IoT Component - addressed in versions 8.7.20, 8.8.16, 9.0.6
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache HTTP Server
- Gentoo update for Apache
- OpenSUSE Linux update for apache2
- OpenSUSE Linux update for apache2
- Amazon Linux AMI update for httpd24
- Debian update for apache2
- Resource management error in apache2 (Alpine package)
- OpenSUSE Linux update for apache2
- Red Hat Software Collections 1 for RHEL 7.7 update for Apache HTTP Server
- Red Hat Enterprise Linux 8 update for the httpd:2.4 module
- Multiple vulnerabilities in DELL Secure Connect Gateway Security
- openEuler 20.03 LTS update for httpd
- Amazon Linux AMI update for httpd24
- Amazon Linux AMI update for httpd24
- Multiple vulnerabilities in IBM Maximo Application Suite - IoT Component
- Ubuntu update for apache2
- Fedora 32 update for mod_http2
- Fedora 31 update for mod_http2