oss-sec mailing list archives

Re: CVE-2021-31618: Apache httpd: NULL pointer dereference on specially crafted HTTP/2 request


From: Christian Fischer <christian.fischer () greenbone net>
Date: Wed, 13 Mar 2024 15:13:48 +0100

Hello,

i'm usually not a fan of bumping such old threads but i'm recently stumbled over this and it seems that this:

On 10.06.21 7:18 PM, Christophe JAILLET wrote:
in fact it was fixed in 2.4.47

doesn't reflect what's currently getting stated on [1] which is:

> This issue affected *snip* Apache HTTP Server version 2.4.47 only
> *snip*
> Affects 2.4.47

Regards,

[1] https://httpd.apache.org/security/vulnerabilities_24.html


Current thread: