Input validation error in Apache HTTP Server - CVE-2020-9490

 

Input validation error in Apache HTTP Server - CVE-2020-9490

Published: August 8, 2020


Vulnerability identifier: #VU35880
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-9490
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input when processing Cache-Digest header in HTTP/2 request. A remote attacker can pass specially crafted HTTP/2 request to the Apache HTTP Server, trigger the server to send the HTTP/2 PUSH and perform a denial of service (DoS) attack.


Affected software

Apache HTTP Server
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Opensuse
Ubuntu
openEuler
Fedora
apache2 (Alpine package)
apache2 (Debian package)
mod_http2
apache2-bin (Ubuntu package)
apache2 (Ubuntu package)
httpd24-httpd (Red Hat package)
libapache2-mod-proxy-uwsgi (Ubuntu package)
mod_ssl
mod_session
mod_md
httpd
httpd-filesystem
httpd-help
httpd-debuginfo
httpd-debugsource
httpd-devel
httpd-tools
mod_ldap
mod_proxy_html
httpd24
QNAP QTS
Dell Secure Connect Gateway
Maximo Application Suite - IoT Component

How to mitigate CVE-2020-9490

Install updates from vendor's website.

Configuring the HTTP/2 feature via "H2Push off" will mitigate this vulnerability for unpatched servers.


Apache HTTP Server - update to 2.4.44
apache2 (Debian package) - update to 2.4.38-3+deb10u4
QNAP QTS - update to 4.3.6.1620 20210322
Dell Secure Connect Gateway - update to 5.12.00.10
apache2 (Alpine package) - update to 1.7-0ubuntu1
mod_http2 - addressed in versions 1.15.14-1.fc31, 1.15.14-1.fc32
apache2-bin (Ubuntu package) - addressed in versions 2.4.18-2ubuntu3.17, 2.4.29-1ubuntu4.14, 2.4.41-4ubuntu3.12
apache2 (Ubuntu package) - addressed in versions 2.4.18-2ubuntu3.17, 2.4.29-1ubuntu4.14, 2.4.41-4ubuntu3.19
httpd24-httpd (Red Hat package) - addressed in versions 2.4.34-18.el6.1, 2.4.34-18.el7.1
libapache2-mod-proxy-uwsgi (Ubuntu package) - update to 2.4.41-4ubuntu3.1
mod_ssl - update to 2.4.43-3
mod_session - update to 2.4.43-3
mod_md - update to 2.4.43-3
httpd - update to 2.4.43-3
httpd-filesystem - update to 2.4.43-3
httpd-help - update to 2.4.43-3
httpd-debuginfo - update to 2.4.43-3
httpd-debugsource - update to 2.4.43-3
httpd-devel - update to 2.4.43-3
httpd-tools - update to 2.4.43-3
mod_ldap - update to 2.4.43-3
mod_proxy_html - update to 2.4.43-3
httpd24 - update to 2.4.46-1.90
Maximo Application Suite - IoT Component - addressed in versions 8.7.20, 8.8.16, 9.0.6

External References

Related Security Bulletins