NULL pointer dereference in Apache HTTP Server - CVE-2020-13950
Published: June 3, 2021 / Updated: July 20, 2022
Vulnerability identifier: #VU53778
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-13950
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in mod_proxy_http. A remote attacker can pass specially crafted data to the application and perform a denial of service (DoS) attack.
Affected software
Apache HTTP Server
Amazon Linux AMI
Gentoo Linux
IBM i
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Oracle Linux
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Slackware Linux
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Server Applications
Ubuntu
openEuler
Fedora
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-apr (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
jbcs-httpd24-curl (Red Hat package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
SUSE Linux Enterprise Module for Packagehub Subpackages
apache2 (Ubuntu package)
apache2-bin (Ubuntu package)
apache2-prefork-debuginfo
apache2-utils-debuginfo
apache2-utils
apache2-prefork
apache2
apache2-event-debuginfo
apache2-doc
apache2-event
apache2-debuginfo
apache2-debugsource
apache2-devel
apache2-worker
apache2-worker-debuginfo
mod_session
mod_ldap
httpd-debuginfo
httpd-debugsource
httpd-tools
httpd-devel
mod_md
mod_ssl
httpd
mod_proxy_html
httpd-help
httpd-filesystem
Cloud Pak for Security (CP4S)
JBoss Core Services
EasyApache
IBM Rational Build Forge
IBM Power Hardware Management Console (HMC)
IBM Hardware Management Console
Amazon Linux AMI
Gentoo Linux
IBM i
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Oracle Linux
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Slackware Linux
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Server Applications
Ubuntu
openEuler
Fedora
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-apr (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
jbcs-httpd24-curl (Red Hat package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
SUSE Linux Enterprise Module for Packagehub Subpackages
apache2 (Ubuntu package)
apache2-bin (Ubuntu package)
apache2-prefork-debuginfo
apache2-utils-debuginfo
apache2-utils
apache2-prefork
apache2
apache2-event-debuginfo
apache2-doc
apache2-event
apache2-debuginfo
apache2-debugsource
apache2-devel
apache2-worker
apache2-worker-debuginfo
mod_session
mod_ldap
httpd-debuginfo
httpd-debugsource
httpd-tools
httpd-devel
mod_md
mod_ssl
httpd
mod_proxy_html
httpd-help
httpd-filesystem
Cloud Pak for Security (CP4S)
JBoss Core Services
EasyApache
IBM Rational Build Forge
IBM Power Hardware Management Console (HMC)
IBM Hardware Management Console
How to mitigate CVE-2020-13950
Install updates from vendor's website.
Apache HTTP Server - update to 2.4.47
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-22.el8jbcs, 0.4.10-22.jbcs.el7
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-7.el8jbcs, 1.0.0-7.jbcs.el7
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-84.el8jbcs, 1.6.1-84.jbcs.el7
jbcs-httpd24-apr (Red Hat package) - addressed in versions 1.6.3-107.el8jbcs, 1.6.3-107.jbcs.el7
Cloud Pak for Security (CP4S) - update to 1.10.7.0
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.7-21.el8jbcs, 1.15.7-21.jbcs.el7
jbcs-httpd24-nghttp2 (Red Hat package) - addressed in versions 1.39.2-39.el8jbcs, 1.39.2-39.jbcs.el7
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.0.8-40.el8jbcs, 2.0.8-40.jbcs.el7
JBoss Core Services - update to 2.4.37 SP10
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.37-78.el8jbcs, 2.4.37-78.jbcs.el7
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.2-67.GA.el8jbcs, 2.9.2-67.GA.jbcs.el7
EasyApache - update to 4 2021-6-2
jbcs-httpd24-curl (Red Hat package) - addressed in versions 7.78.0-2.el8jbcs, 7.78.0-2.jbcs.el7
IBM Rational Build Forge - update to 8.0.0.21
apache2 (Ubuntu package) - addressed in versions 2.4.29-1ubuntu4.16, 2.4.41-4ubuntu3.3, 2.4.46-1ubuntu1.2, 2.4.46-4ubuntu1.1
apache2-bin (Ubuntu package) - addressed in versions 2.4.29-1ubuntu4.16, 2.4.41-4ubuntu3.3, 2.4.46-1ubuntu1.2, 2.4.46-4ubuntu1.1
apache2-prefork-debuginfo - update to 2.4.43-3.22.1
apache2-utils-debuginfo - update to 2.4.43-3.22.1
apache2-utils - update to 2.4.43-3.22.1
apache2-prefork - update to 2.4.43-3.22.1
apache2 - update to 2.4.43-3.22.1
apache2-event-debuginfo - update to 2.4.43-3.22.1
apache2-doc - update to 2.4.43-3.22.1
apache2-event - update to 2.4.43-3.22.1
apache2-debuginfo - update to 2.4.43-3.22.1
apache2-debugsource - update to 2.4.43-3.22.1
apache2-devel - update to 2.4.43-3.22.1
apache2-worker - update to 2.4.43-3.22.1
apache2-worker-debuginfo - update to 2.4.43-3.22.1
mod_session - update to 2.4.43-7
mod_ldap - update to 2.4.43-7
httpd-debuginfo - update to 2.4.43-7
httpd-debugsource - update to 2.4.43-7
httpd-tools - update to 2.4.43-7
httpd-devel - update to 2.4.43-7
mod_md - update to 2.4.43-7
mod_ssl - update to 2.4.43-7
httpd - update to 2.4.43-7
mod_proxy_html - update to 2.4.43-7
httpd-help - update to 2.4.43-7
httpd-filesystem - update to 2.4.43-7
httpd - addressed in versions 2.4.49-1.fc34, 2.4.49-1.fc35
IBM Hardware Management Console - addressed in versions 9.2.950.0 SP3 ppc, 9.2.950.0 SP3 x86, 10.1.1020.0 SP1 ppc, 10.1.1020.0 SP1 x86
IBM Power Hardware Management Console (HMC) - addressed in versions 9.2.950.0 SP3, 10.1.1020.0 SP1
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-22.el8jbcs, 0.4.10-22.jbcs.el7
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-7.el8jbcs, 1.0.0-7.jbcs.el7
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-84.el8jbcs, 1.6.1-84.jbcs.el7
jbcs-httpd24-apr (Red Hat package) - addressed in versions 1.6.3-107.el8jbcs, 1.6.3-107.jbcs.el7
Cloud Pak for Security (CP4S) - update to 1.10.7.0
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.7-21.el8jbcs, 1.15.7-21.jbcs.el7
jbcs-httpd24-nghttp2 (Red Hat package) - addressed in versions 1.39.2-39.el8jbcs, 1.39.2-39.jbcs.el7
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.0.8-40.el8jbcs, 2.0.8-40.jbcs.el7
JBoss Core Services - update to 2.4.37 SP10
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.37-78.el8jbcs, 2.4.37-78.jbcs.el7
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.2-67.GA.el8jbcs, 2.9.2-67.GA.jbcs.el7
EasyApache - update to 4 2021-6-2
jbcs-httpd24-curl (Red Hat package) - addressed in versions 7.78.0-2.el8jbcs, 7.78.0-2.jbcs.el7
IBM Rational Build Forge - update to 8.0.0.21
apache2 (Ubuntu package) - addressed in versions 2.4.29-1ubuntu4.16, 2.4.41-4ubuntu3.3, 2.4.46-1ubuntu1.2, 2.4.46-4ubuntu1.1
apache2-bin (Ubuntu package) - addressed in versions 2.4.29-1ubuntu4.16, 2.4.41-4ubuntu3.3, 2.4.46-1ubuntu1.2, 2.4.46-4ubuntu1.1
apache2-prefork-debuginfo - update to 2.4.43-3.22.1
apache2-utils-debuginfo - update to 2.4.43-3.22.1
apache2-utils - update to 2.4.43-3.22.1
apache2-prefork - update to 2.4.43-3.22.1
apache2 - update to 2.4.43-3.22.1
apache2-event-debuginfo - update to 2.4.43-3.22.1
apache2-doc - update to 2.4.43-3.22.1
apache2-event - update to 2.4.43-3.22.1
apache2-debuginfo - update to 2.4.43-3.22.1
apache2-debugsource - update to 2.4.43-3.22.1
apache2-devel - update to 2.4.43-3.22.1
apache2-worker - update to 2.4.43-3.22.1
apache2-worker-debuginfo - update to 2.4.43-3.22.1
mod_session - update to 2.4.43-7
mod_ldap - update to 2.4.43-7
httpd-debuginfo - update to 2.4.43-7
httpd-debugsource - update to 2.4.43-7
httpd-tools - update to 2.4.43-7
httpd-devel - update to 2.4.43-7
mod_md - update to 2.4.43-7
mod_ssl - update to 2.4.43-7
httpd - update to 2.4.43-7
mod_proxy_html - update to 2.4.43-7
httpd-help - update to 2.4.43-7
httpd-filesystem - update to 2.4.43-7
httpd - addressed in versions 2.4.49-1.fc34, 2.4.49-1.fc35
IBM Hardware Management Console - addressed in versions 9.2.950.0 SP3 ppc, 9.2.950.0 SP3 x86, 10.1.1020.0 SP1 ppc, 10.1.1020.0 SP1 x86
IBM Power Hardware Management Console (HMC) - addressed in versions 9.2.950.0 SP3, 10.1.1020.0 SP1
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache HTTP Server
- cPanel update for EasyApache
- Slackware Linux update for httpd
- Amazon Linux AMI update for httpd24
- Gentoo update for Apache
- Multiple vulnerabilities in Red Hat JBoss Core Services Apache HTTP Server
- SUSE update for apache2
- Ubuntu update for apache2
- Red Hat Enterprise Linux 8.6 update for the httpd:2.4 module
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in IBM i
- Denial of service in IBM Power Hardware Management Console (HMC) Apache HTTP server
- NULL pointer dereference in IBM Hardware Management Console
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- openEuler 20.03 LTS SP1 update for httpd
- Fedora 34 update for httpd
- Fedora 35 update for httpd
- Multiple vulnerabilities in IBM Rational Build Forge