Input validation error in Apache HTTP Server - CVE-2020-9490
Published: August 8, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input when processing Cache-Digest header in HTTP/2 request. A remote attacker can pass specially crafted HTTP/2 request to the Apache HTTP Server, trigger the server to send the HTTP/2
PUSH and perform a denial of service (DoS) attack.
Affected software
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Opensuse
Ubuntu
openEuler
Fedora
apache2 (Alpine package)
apache2 (Debian package)
mod_http2
apache2-bin (Ubuntu package)
apache2 (Ubuntu package)
httpd24-httpd (Red Hat package)
libapache2-mod-proxy-uwsgi (Ubuntu package)
mod_ssl
mod_session
mod_md
httpd
httpd-filesystem
httpd-help
httpd-debuginfo
httpd-debugsource
httpd-devel
httpd-tools
mod_ldap
mod_proxy_html
httpd24
QNAP QTS
Dell Secure Connect Gateway
Maximo Application Suite - IoT Component
How to mitigate CVE-2020-9490
Install updates from vendor's website.
Configuring the HTTP/2 feature via "H2Push off" will mitigate this vulnerability for unpatched servers.
apache2 (Debian package) - update to 2.4.38-3+deb10u4
QNAP QTS - update to 4.3.6.1620 20210322
Dell Secure Connect Gateway - update to 5.12.00.10
apache2 (Alpine package) - update to 1.7-0ubuntu1
mod_http2 - addressed in versions 1.15.14-1.fc31, 1.15.14-1.fc32
apache2-bin (Ubuntu package) - addressed in versions 2.4.18-2ubuntu3.17, 2.4.29-1ubuntu4.14, 2.4.41-4ubuntu3.12
apache2 (Ubuntu package) - addressed in versions 2.4.18-2ubuntu3.17, 2.4.29-1ubuntu4.14, 2.4.41-4ubuntu3.19
httpd24-httpd (Red Hat package) - addressed in versions 2.4.34-18.el6.1, 2.4.34-18.el7.1
libapache2-mod-proxy-uwsgi (Ubuntu package) - update to 2.4.41-4ubuntu3.1
mod_ssl - update to 2.4.43-3
mod_session - update to 2.4.43-3
mod_md - update to 2.4.43-3
httpd - update to 2.4.43-3
httpd-filesystem - update to 2.4.43-3
httpd-help - update to 2.4.43-3
httpd-debuginfo - update to 2.4.43-3
httpd-debugsource - update to 2.4.43-3
httpd-devel - update to 2.4.43-3
httpd-tools - update to 2.4.43-3
mod_ldap - update to 2.4.43-3
mod_proxy_html - update to 2.4.43-3
httpd24 - update to 2.4.46-1.90
Maximo Application Suite - IoT Component - addressed in versions 8.7.20, 8.8.16, 9.0.6
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache HTTP Server
- Gentoo update for Apache
- OpenSUSE Linux update for apache2
- OpenSUSE Linux update for apache2
- Amazon Linux AMI update for httpd24
- Debian update for apache2
- Input validation error in apache2 (Alpine package)
- OpenSUSE Linux update for apache2
- Multiple vulnerabilities in QNAP QTS
- Multiple vulnerabilities in DELL Secure Connect Gateway Security
- Red Hat Software Collections update for httpd24-httpd
- openEuler 20.03 LTS update for httpd
- Amazon Linux AMI update for httpd24
- Amazon Linux AMI update for httpd24
- Multiple vulnerabilities in IBM Maximo Application Suite - IoT Component
- Ubuntu update for apache2
- Red Hat Enterprise Linux 8 update for the httpd:2.4 module
- Red Hat Enterprise Linux 8 update for the httpd:2.4 module
- Fedora 32 update for mod_http2
- Fedora 31 update for mod_http2