NULL pointer dereference in Apache HTTP Server - CVE-2024-36387

 

NULL pointer dereference in Apache HTTP Server - CVE-2024-36387

Published: July 1, 2024


Vulnerability identifier: #VU93538
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-36387
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error when handling websocket over HTTP/2 connections. A remote attacker can send specially crafted data to the web server and perform a denial of service (DoS) attack.


Affected software

Apache HTTP Server
HP-UX Apache Web Server
Gentoo Linux
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Slackware Linux
SUSE Package Hub 15
Server Applications Module
Basesystem Module
openSUSE Leap
Ubuntu
Anolis OS
openEuler
Fedora
JBoss Core Services
EasyApache
OpenShift Logging
IBM Rational Build Forge
EMC NetWorker Server
SecurityCenter
mod_http2
mod_http2-debuginfo
mod_http2-debugsource
mod_http2-help
http2 (Red Hat package)
apache2 (Ubuntu package)
httpd-devel
httpd-help
httpd-filesystem
mod_ssl
mod_session
mod_proxy_html
mod_md
mod_ldap
httpd-tools
httpd-debugsource
httpd-debuginfo
httpd
apache2-worker-debugsource
apache2-manual
apache2-devel
apache2-debugsource
apache2-utils-debugsource
apache2-utils-debuginfo
apache2-prefork-debugsource
apache2
apache2-prefork
apache2-event-debugsource
apache2-debuginfo
apache2-event-debuginfo
apache2-worker
apache2-utils
apache2-worker-debuginfo
apache2-event
apache2-prefork-debuginfo
apache2 (Debian package)
www-servers/apache
httpd-manual
httpd-doc
mod_lua
httpd-core
IBM Aspera Console
NetWorker Management Console (NMC)

How to mitigate CVE-2024-36387

Install updates from vendor's website.

Apache HTTP Server - update to 2.4.60
JBoss Core Services - update to 2.4.62
EasyApache - update to 4 2024-7-10
SecurityCenter - update to SC-202408.1
mod_http2 - update to 2.0.25-3
mod_http2-debuginfo - update to 2.0.25-3
mod_http2-debugsource - update to 2.0.25-3
mod_http2-help - update to 2.0.25-3
http2 (Red Hat package) - update to 2.0.26-2.el9_4.1
mod_http2 - addressed in versions 2.0.29-1.fc39, 2.0.29-1.fc40
apache2 (Ubuntu package) - addressed in versions 2.4.41-4ubuntu3.19, 2.4.41-4ubuntu3.20, 2.4.52-1ubuntu4.10, 2.4.52-1ubuntu4.11, 2.4.57-2ubuntu2.5, 2.4.58-1ubuntu8.2, 2.4.58-1ubuntu8.3
httpd-devel - update to 2.4.58-6
httpd-help - update to 2.4.58-6
httpd-filesystem - update to 2.4.58-6
mod_ssl - update to 2.4.58-6
mod_session - update to 2.4.58-6
mod_proxy_html - update to 2.4.58-6
mod_md - update to 2.4.58-6
mod_ldap - update to 2.4.58-6
httpd-tools - update to 2.4.58-6
httpd-debugsource - update to 2.4.58-6
httpd-debuginfo - update to 2.4.58-6
httpd - update to 2.4.58-6
apache2-worker-debugsource - update to 2.4.58-150600.5.18.1
apache2-manual - update to 2.4.58-150600.5.18.1
apache2-devel - update to 2.4.58-150600.5.18.1
apache2-debugsource - update to 2.4.58-150600.5.18.1
apache2-utils-debugsource - update to 2.4.58-150600.5.18.1
apache2-utils-debuginfo - update to 2.4.58-150600.5.18.1
apache2-prefork-debugsource - update to 2.4.58-150600.5.18.1
apache2 - update to 2.4.58-150600.5.18.1
apache2-prefork - update to 2.4.58-150600.5.18.1
apache2-event-debugsource - update to 2.4.58-150600.5.18.1
apache2-debuginfo - update to 2.4.58-150600.5.18.1
apache2-event-debuginfo - update to 2.4.58-150600.5.18.1
apache2-worker - update to 2.4.58-150600.5.18.1
apache2-utils - update to 2.4.58-150600.5.18.1
apache2-worker-debuginfo - update to 2.4.58-150600.5.18.1
apache2-event - update to 2.4.58-150600.5.18.1
apache2-prefork-debuginfo - update to 2.4.58-150600.5.18.1
httpd - update to 2.4.60
apache2 (Debian package) - addressed in versions 2.4.61-1~deb11u1, 2.4.61-1~deb12u1
HP-UX Apache Web Server - update to 2.4.62.00
www-servers/apache - update to 2.4.62
httpd-tools - update to 2.4.62-1
httpd-manual - update to 2.4.62-1
httpd-filesystem - update to 2.4.62-1
httpd-doc - update to 2.4.62-1
mod_ssl - update to 2.4.62-1
mod_session - update to 2.4.62-1
mod_proxy_html - update to 2.4.62-1
mod_lua - update to 2.4.62-1
mod_ldap - update to 2.4.62-1
httpd-devel - update to 2.4.62-1
httpd-core - update to 2.4.62-1
httpd - update to 2.4.62-1
IBM Aspera Console - update to 3.4.5
OpenShift Logging - update to 5.8.16
IBM Rational Build Forge - update to 8.0.0.27
EMC NetWorker Server - update to 19.10.0.5
NetWorker Management Console (NMC) - update to 19.10.0.5

External References

Related Security Bulletins