NULL pointer dereference in Apache HTTP Server - CVE-2024-36387
Published: July 1, 2024
Vulnerability identifier: #VU93538
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-36387
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error when handling websocket over HTTP/2 connections. A remote attacker can send specially crafted data to the web server and perform a denial of service (DoS) attack.
Affected software
Apache HTTP Server
HP-UX Apache Web Server
Gentoo Linux
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Slackware Linux
SUSE Package Hub 15
Server Applications Module
Basesystem Module
openSUSE Leap
Ubuntu
Anolis OS
openEuler
Fedora
JBoss Core Services
EasyApache
OpenShift Logging
IBM Rational Build Forge
EMC NetWorker Server
SecurityCenter
mod_http2
mod_http2-debuginfo
mod_http2-debugsource
mod_http2-help
http2 (Red Hat package)
apache2 (Ubuntu package)
httpd-devel
httpd-help
httpd-filesystem
mod_ssl
mod_session
mod_proxy_html
mod_md
mod_ldap
httpd-tools
httpd-debugsource
httpd-debuginfo
httpd
apache2-worker-debugsource
apache2-manual
apache2-devel
apache2-debugsource
apache2-utils-debugsource
apache2-utils-debuginfo
apache2-prefork-debugsource
apache2
apache2-prefork
apache2-event-debugsource
apache2-debuginfo
apache2-event-debuginfo
apache2-worker
apache2-utils
apache2-worker-debuginfo
apache2-event
apache2-prefork-debuginfo
apache2 (Debian package)
www-servers/apache
httpd-manual
httpd-doc
mod_lua
httpd-core
IBM Aspera Console
NetWorker Management Console (NMC)
HP-UX Apache Web Server
Gentoo Linux
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Slackware Linux
SUSE Package Hub 15
Server Applications Module
Basesystem Module
openSUSE Leap
Ubuntu
Anolis OS
openEuler
Fedora
JBoss Core Services
EasyApache
OpenShift Logging
IBM Rational Build Forge
EMC NetWorker Server
SecurityCenter
mod_http2
mod_http2-debuginfo
mod_http2-debugsource
mod_http2-help
http2 (Red Hat package)
apache2 (Ubuntu package)
httpd-devel
httpd-help
httpd-filesystem
mod_ssl
mod_session
mod_proxy_html
mod_md
mod_ldap
httpd-tools
httpd-debugsource
httpd-debuginfo
httpd
apache2-worker-debugsource
apache2-manual
apache2-devel
apache2-debugsource
apache2-utils-debugsource
apache2-utils-debuginfo
apache2-prefork-debugsource
apache2
apache2-prefork
apache2-event-debugsource
apache2-debuginfo
apache2-event-debuginfo
apache2-worker
apache2-utils
apache2-worker-debuginfo
apache2-event
apache2-prefork-debuginfo
apache2 (Debian package)
www-servers/apache
httpd-manual
httpd-doc
mod_lua
httpd-core
IBM Aspera Console
NetWorker Management Console (NMC)
How to mitigate CVE-2024-36387
Install updates from vendor's website.
Apache HTTP Server - update to 2.4.60
JBoss Core Services - update to 2.4.62
EasyApache - update to 4 2024-7-10
SecurityCenter - update to SC-202408.1
mod_http2 - update to 2.0.25-3
mod_http2-debuginfo - update to 2.0.25-3
mod_http2-debugsource - update to 2.0.25-3
mod_http2-help - update to 2.0.25-3
http2 (Red Hat package) - update to 2.0.26-2.el9_4.1
mod_http2 - addressed in versions 2.0.29-1.fc39, 2.0.29-1.fc40
apache2 (Ubuntu package) - addressed in versions 2.4.41-4ubuntu3.19, 2.4.41-4ubuntu3.20, 2.4.52-1ubuntu4.10, 2.4.52-1ubuntu4.11, 2.4.57-2ubuntu2.5, 2.4.58-1ubuntu8.2, 2.4.58-1ubuntu8.3
httpd-devel - update to 2.4.58-6
httpd-help - update to 2.4.58-6
httpd-filesystem - update to 2.4.58-6
mod_ssl - update to 2.4.58-6
mod_session - update to 2.4.58-6
mod_proxy_html - update to 2.4.58-6
mod_md - update to 2.4.58-6
mod_ldap - update to 2.4.58-6
httpd-tools - update to 2.4.58-6
httpd-debugsource - update to 2.4.58-6
httpd-debuginfo - update to 2.4.58-6
httpd - update to 2.4.58-6
apache2-worker-debugsource - update to 2.4.58-150600.5.18.1
apache2-manual - update to 2.4.58-150600.5.18.1
apache2-devel - update to 2.4.58-150600.5.18.1
apache2-debugsource - update to 2.4.58-150600.5.18.1
apache2-utils-debugsource - update to 2.4.58-150600.5.18.1
apache2-utils-debuginfo - update to 2.4.58-150600.5.18.1
apache2-prefork-debugsource - update to 2.4.58-150600.5.18.1
apache2 - update to 2.4.58-150600.5.18.1
apache2-prefork - update to 2.4.58-150600.5.18.1
apache2-event-debugsource - update to 2.4.58-150600.5.18.1
apache2-debuginfo - update to 2.4.58-150600.5.18.1
apache2-event-debuginfo - update to 2.4.58-150600.5.18.1
apache2-worker - update to 2.4.58-150600.5.18.1
apache2-utils - update to 2.4.58-150600.5.18.1
apache2-worker-debuginfo - update to 2.4.58-150600.5.18.1
apache2-event - update to 2.4.58-150600.5.18.1
apache2-prefork-debuginfo - update to 2.4.58-150600.5.18.1
httpd - update to 2.4.60
apache2 (Debian package) - addressed in versions 2.4.61-1~deb11u1, 2.4.61-1~deb12u1
HP-UX Apache Web Server - update to 2.4.62.00
www-servers/apache - update to 2.4.62
httpd-tools - update to 2.4.62-1
httpd-manual - update to 2.4.62-1
httpd-filesystem - update to 2.4.62-1
httpd-doc - update to 2.4.62-1
mod_ssl - update to 2.4.62-1
mod_session - update to 2.4.62-1
mod_proxy_html - update to 2.4.62-1
mod_lua - update to 2.4.62-1
mod_ldap - update to 2.4.62-1
httpd-devel - update to 2.4.62-1
httpd-core - update to 2.4.62-1
httpd - update to 2.4.62-1
IBM Aspera Console - update to 3.4.5
OpenShift Logging - update to 5.8.16
IBM Rational Build Forge - update to 8.0.0.27
EMC NetWorker Server - update to 19.10.0.5
NetWorker Management Console (NMC) - update to 19.10.0.5
JBoss Core Services - update to 2.4.62
EasyApache - update to 4 2024-7-10
SecurityCenter - update to SC-202408.1
mod_http2 - update to 2.0.25-3
mod_http2-debuginfo - update to 2.0.25-3
mod_http2-debugsource - update to 2.0.25-3
mod_http2-help - update to 2.0.25-3
http2 (Red Hat package) - update to 2.0.26-2.el9_4.1
mod_http2 - addressed in versions 2.0.29-1.fc39, 2.0.29-1.fc40
apache2 (Ubuntu package) - addressed in versions 2.4.41-4ubuntu3.19, 2.4.41-4ubuntu3.20, 2.4.52-1ubuntu4.10, 2.4.52-1ubuntu4.11, 2.4.57-2ubuntu2.5, 2.4.58-1ubuntu8.2, 2.4.58-1ubuntu8.3
httpd-devel - update to 2.4.58-6
httpd-help - update to 2.4.58-6
httpd-filesystem - update to 2.4.58-6
mod_ssl - update to 2.4.58-6
mod_session - update to 2.4.58-6
mod_proxy_html - update to 2.4.58-6
mod_md - update to 2.4.58-6
mod_ldap - update to 2.4.58-6
httpd-tools - update to 2.4.58-6
httpd-debugsource - update to 2.4.58-6
httpd-debuginfo - update to 2.4.58-6
httpd - update to 2.4.58-6
apache2-worker-debugsource - update to 2.4.58-150600.5.18.1
apache2-manual - update to 2.4.58-150600.5.18.1
apache2-devel - update to 2.4.58-150600.5.18.1
apache2-debugsource - update to 2.4.58-150600.5.18.1
apache2-utils-debugsource - update to 2.4.58-150600.5.18.1
apache2-utils-debuginfo - update to 2.4.58-150600.5.18.1
apache2-prefork-debugsource - update to 2.4.58-150600.5.18.1
apache2 - update to 2.4.58-150600.5.18.1
apache2-prefork - update to 2.4.58-150600.5.18.1
apache2-event-debugsource - update to 2.4.58-150600.5.18.1
apache2-debuginfo - update to 2.4.58-150600.5.18.1
apache2-event-debuginfo - update to 2.4.58-150600.5.18.1
apache2-worker - update to 2.4.58-150600.5.18.1
apache2-utils - update to 2.4.58-150600.5.18.1
apache2-worker-debuginfo - update to 2.4.58-150600.5.18.1
apache2-event - update to 2.4.58-150600.5.18.1
apache2-prefork-debuginfo - update to 2.4.58-150600.5.18.1
httpd - update to 2.4.60
apache2 (Debian package) - addressed in versions 2.4.61-1~deb11u1, 2.4.61-1~deb12u1
HP-UX Apache Web Server - update to 2.4.62.00
www-servers/apache - update to 2.4.62
httpd-tools - update to 2.4.62-1
httpd-manual - update to 2.4.62-1
httpd-filesystem - update to 2.4.62-1
httpd-doc - update to 2.4.62-1
mod_ssl - update to 2.4.62-1
mod_session - update to 2.4.62-1
mod_proxy_html - update to 2.4.62-1
mod_lua - update to 2.4.62-1
mod_ldap - update to 2.4.62-1
httpd-devel - update to 2.4.62-1
httpd-core - update to 2.4.62-1
httpd - update to 2.4.62-1
IBM Aspera Console - update to 3.4.5
OpenShift Logging - update to 5.8.16
IBM Rational Build Forge - update to 8.0.0.27
EMC NetWorker Server - update to 19.10.0.5
NetWorker Management Console (NMC) - update to 19.10.0.5
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache HTTP Server
- Slackware Linux update for httpd
- Ubuntu update for apache2
- Ubuntu update for apache2
- Debian update for apache2
- openEuler 24.03 LTS update for mod_http2
- openEuler 24.03 LTS update for httpd
- SUSE update for apache2
- Fedora 40 update for mod_http2
- Fedora 39 update for mod_http2
- Multiple vulnerabilities in Tenable Security Center
- Gentoo update for Apache HTTPD
- Multiple vulnerabilities in IBM Aspera Console
- Multiple vulnerabilities in IBM Rational Build Forge
- Multiple vulnerabilities in cPanel EasyApache
- Multiple vulnerabilities in Dell NetWorker And NetWorker Management Console
- Red Hat Enterprise Linux 9 update for mod_http2
- Multiple vulnerabilities in OpenShift Logging 5.8
- Multiple vulnerabilities in HPE HP-UX Apache Web Server
- Anolis OS update for httpd
- Multiple vulnerabilities in Red Hat JBoss Core Services Apache HTTP Server