NULL pointer dereference in Apache HTTP Server - CVE-2020-13950

 

NULL pointer dereference in Apache HTTP Server - CVE-2020-13950

Published: June 3, 2021 / Updated: July 20, 2022


Vulnerability identifier: #VU53778
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-13950
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error in mod_proxy_http. A remote attacker can pass specially crafted data to the application and perform a denial of service (DoS) attack.


Affected software

Apache HTTP Server
Amazon Linux AMI
Gentoo Linux
IBM i
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Oracle Linux
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Slackware Linux
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Server Applications
Ubuntu
openEuler
Fedora
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-apr (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
jbcs-httpd24-curl (Red Hat package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
SUSE Linux Enterprise Module for Packagehub Subpackages
apache2 (Ubuntu package)
apache2-bin (Ubuntu package)
apache2-prefork-debuginfo
apache2-utils-debuginfo
apache2-utils
apache2-prefork
apache2
apache2-event-debuginfo
apache2-doc
apache2-event
apache2-debuginfo
apache2-debugsource
apache2-devel
apache2-worker
apache2-worker-debuginfo
mod_session
mod_ldap
httpd-debuginfo
httpd-debugsource
httpd-tools
httpd-devel
mod_md
mod_ssl
httpd
mod_proxy_html
httpd-help
httpd-filesystem
Cloud Pak for Security (CP4S)
JBoss Core Services
EasyApache
IBM Rational Build Forge
IBM Power Hardware Management Console (HMC)
IBM Hardware Management Console

How to mitigate CVE-2020-13950

Install updates from vendor's website.

Apache HTTP Server - update to 2.4.47
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-22.el8jbcs, 0.4.10-22.jbcs.el7
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-7.el8jbcs, 1.0.0-7.jbcs.el7
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-84.el8jbcs, 1.6.1-84.jbcs.el7
jbcs-httpd24-apr (Red Hat package) - addressed in versions 1.6.3-107.el8jbcs, 1.6.3-107.jbcs.el7
Cloud Pak for Security (CP4S) - update to 1.10.7.0
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.7-21.el8jbcs, 1.15.7-21.jbcs.el7
jbcs-httpd24-nghttp2 (Red Hat package) - addressed in versions 1.39.2-39.el8jbcs, 1.39.2-39.jbcs.el7
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.0.8-40.el8jbcs, 2.0.8-40.jbcs.el7
JBoss Core Services - update to 2.4.37 SP10
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.37-78.el8jbcs, 2.4.37-78.jbcs.el7
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.2-67.GA.el8jbcs, 2.9.2-67.GA.jbcs.el7
EasyApache - update to 4 2021-6-2
jbcs-httpd24-curl (Red Hat package) - addressed in versions 7.78.0-2.el8jbcs, 7.78.0-2.jbcs.el7
IBM Rational Build Forge - update to 8.0.0.21
apache2 (Ubuntu package) - addressed in versions 2.4.29-1ubuntu4.16, 2.4.41-4ubuntu3.3, 2.4.46-1ubuntu1.2, 2.4.46-4ubuntu1.1
apache2-bin (Ubuntu package) - addressed in versions 2.4.29-1ubuntu4.16, 2.4.41-4ubuntu3.3, 2.4.46-1ubuntu1.2, 2.4.46-4ubuntu1.1
apache2-prefork-debuginfo - update to 2.4.43-3.22.1
apache2-utils-debuginfo - update to 2.4.43-3.22.1
apache2-utils - update to 2.4.43-3.22.1
apache2-prefork - update to 2.4.43-3.22.1
apache2 - update to 2.4.43-3.22.1
apache2-event-debuginfo - update to 2.4.43-3.22.1
apache2-doc - update to 2.4.43-3.22.1
apache2-event - update to 2.4.43-3.22.1
apache2-debuginfo - update to 2.4.43-3.22.1
apache2-debugsource - update to 2.4.43-3.22.1
apache2-devel - update to 2.4.43-3.22.1
apache2-worker - update to 2.4.43-3.22.1
apache2-worker-debuginfo - update to 2.4.43-3.22.1
mod_session - update to 2.4.43-7
mod_ldap - update to 2.4.43-7
httpd-debuginfo - update to 2.4.43-7
httpd-debugsource - update to 2.4.43-7
httpd-tools - update to 2.4.43-7
httpd-devel - update to 2.4.43-7
mod_md - update to 2.4.43-7
mod_ssl - update to 2.4.43-7
httpd - update to 2.4.43-7
mod_proxy_html - update to 2.4.43-7
httpd-help - update to 2.4.43-7
httpd-filesystem - update to 2.4.43-7
httpd - addressed in versions 2.4.49-1.fc34, 2.4.49-1.fc35
IBM Hardware Management Console - addressed in versions 9.2.950.0 SP3 ppc, 9.2.950.0 SP3 x86, 10.1.1020.0 SP1 ppc, 10.1.1020.0 SP1 x86
IBM Power Hardware Management Console (HMC) - addressed in versions 9.2.950.0 SP3, 10.1.1020.0 SP1

External References

Related Security Bulletins