oss-sec mailing list archives
CVE-2020-11993: Apache httpd: Push Diary Crash on Specifically Crafted HTTP/2 Header
From: Daniel Ruggeri <druggeri () apache org>
Date: Fri, 07 Aug 2020 06:31:38 -0500
CVE-2020-11993: Push Diary Crash on Specifically Crafted HTTP/2 Header Severity: moderate Vendor: Apache Software Foundation Versions Affected: Apache HTTP Server 2.4.20 to 2.4.43 Description: Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above "info" will mitigate this vulnerability for unpatched servers. Mitigation: Credit: Felix Wilhelm of Google Project Zero References: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2020-11993
Current thread:
- CVE-2020-11993: Apache httpd: Push Diary Crash on Specifically Crafted HTTP/2 Header Daniel Ruggeri (Aug 07)