NULL pointer dereference in Apache HTTP Server - CVE-2024-36387
Published: July 1, 2024
Vulnerability identifier: #VU93538
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2024-36387
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Affected software:
Apache HTTP Server
HP-UX Apache Web Server
Gentoo Linux
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Slackware Linux
SUSE Package Hub 15
Server Applications Module
Basesystem Module
openSUSE Leap
Ubuntu
Anolis OS
openEuler
Fedora
JBoss Core Services
EasyApache
OpenShift Logging
IBM Rational Build Forge
EMC NetWorker Server
SecurityCenter
mod_http2
mod_http2-debuginfo
mod_http2-debugsource
mod_http2-help
http2 (Red Hat package)
apache2 (Ubuntu package)
httpd-devel
httpd-help
httpd-filesystem
mod_ssl
mod_session
mod_proxy_html
mod_md
mod_ldap
httpd-tools
httpd-debugsource
httpd-debuginfo
httpd
apache2-worker-debugsource
apache2-manual
apache2-devel
apache2-debugsource
apache2-utils-debugsource
apache2-utils-debuginfo
apache2-prefork-debugsource
apache2
apache2-prefork
apache2-event-debugsource
apache2-debuginfo
apache2-event-debuginfo
apache2-worker
apache2-utils
apache2-worker-debuginfo
apache2-event
apache2-prefork-debuginfo
apache2 (Debian package)
www-servers/apache
httpd-manual
httpd-doc
mod_lua
httpd-core
IBM Aspera Console
NetWorker Management Console (NMC)
Apache HTTP Server
HP-UX Apache Web Server
Gentoo Linux
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Slackware Linux
SUSE Package Hub 15
Server Applications Module
Basesystem Module
openSUSE Leap
Ubuntu
Anolis OS
openEuler
Fedora
JBoss Core Services
EasyApache
OpenShift Logging
IBM Rational Build Forge
EMC NetWorker Server
SecurityCenter
mod_http2
mod_http2-debuginfo
mod_http2-debugsource
mod_http2-help
http2 (Red Hat package)
apache2 (Ubuntu package)
httpd-devel
httpd-help
httpd-filesystem
mod_ssl
mod_session
mod_proxy_html
mod_md
mod_ldap
httpd-tools
httpd-debugsource
httpd-debuginfo
httpd
apache2-worker-debugsource
apache2-manual
apache2-devel
apache2-debugsource
apache2-utils-debugsource
apache2-utils-debuginfo
apache2-prefork-debugsource
apache2
apache2-prefork
apache2-event-debugsource
apache2-debuginfo
apache2-event-debuginfo
apache2-worker
apache2-utils
apache2-worker-debuginfo
apache2-event
apache2-prefork-debuginfo
apache2 (Debian package)
www-servers/apache
httpd-manual
httpd-doc
mod_lua
httpd-core
IBM Aspera Console
NetWorker Management Console (NMC)
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error when handling websocket over HTTP/2 connections. A remote attacker can send specially crafted data to the web server and perform a denial of service (DoS) attack.
How to mitigate CVE-2024-36387
Install updates from vendor's website.