CVE-2019-0196

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

A vulnerability was found in Apache HTTP Server 2.4.17 to 2.4.38. Using fuzzed network input, the http/2 request handling could be made to access freed memory in string comparison when determining the method of a request and thus process the request incorrectly.

References

https://www.debian.org/security/2019/dsa-4422

https://usn.ubuntu.com/3937-1/

https://support.f5.com/csp/article/K44591505

https://seclists.org/bugtraq/2019/Apr/5

https://lists.fedoraproject.org/archives/list/[email protected]/message/YTJPHI3E3OKW7OT7COQXVG7DE7IDQ2OT/

https://lists.fedoraproject.org/archives/list/[email protected]/message/WETXNQWNQLWHV6XNW6YTO5UGDTIWAQGT/

https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E

https://httpd.apache.org/security/vulnerabilities_24.html

http://www.securityfocus.com/bid/107669

http://www.openwall.com/lists/oss-security/2019/04/02/1

http://www.apache.org/dist/httpd/CHANGES_2.4.39

http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00084.html

http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00061.html

http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00051.html

https://security.netapp.com/advisory/ntap-20190617-0002/

https://lists.fedoraproject.org/archives/list/[email protected]/message/XWRYD6JMEJ6O3JKJZFNOYXMJJU5JMEJK/

https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html

https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E

https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03950en_us

https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html

https://access.redhat.com/errata/RHSA-2019:3933

https://access.redhat.com/errata/RHSA-2019:3935

https://access.redhat.com/errata/RHSA-2019:3932

https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E

https://www.oracle.com/security-alerts/cpuapr2020.html

https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E

Details

Source: MITRE

Published: 2019-06-11

Updated: 2021-06-06

Type: CWE-416

Risk Information

CVSS v2

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM

CVSS v3

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Impact Score: 1.4

Exploitability Score: 3.9

Severity: MEDIUM

Tenable Plugins

View all (25 total)

IDNameProductFamilySeverity
145821CentOS 8 : httpd:2.4 (CESA-2020:4751)NessusCentOS Local Security Checks
critical
142762Oracle Linux 8 : httpd:2.4 (ELSA-2020-4751)NessusOracle Linux Local Security Checks
critical
142397RHEL 8 : httpd:2.4 (RHSA-2020:4751)NessusRed Hat Local Security Checks
critical
137799EulerOS Virtualization for ARM 64 3.0.6.0 : httpd (EulerOS-SA-2020-1692)NessusHuawei Local Security Checks
medium
137705RHEL 6 / 7 : Red Hat JBoss Core Services Apache HTTP Server 2.4.37 SP3 (RHSA-2020:2644)NessusRed Hat Local Security Checks
medium
135738EulerOS 2.0 SP8 : httpd (EulerOS-SA-2020-1505)NessusHuawei Local Security Checks
medium
131216RHEL 7 : JBoss Core Services (RHSA-2019:3933) (0-Length Headers Leak) (Data Dribble) (Internal Data Buffering) (Resource Loop)NessusRed Hat Local Security Checks
high
131215RHEL 6 : JBoss Core Services (RHSA-2019:3932) (0-Length Headers Leak) (Data Dribble) (Internal Data Buffering) (Resource Loop)NessusRed Hat Local Security Checks
high
127466Amazon Linux 2 : mod_http2 (ALAS-2019-1264)NessusAmazon Linux Local Security Checks
medium
126777Oracle Enterprise Manager Ops Center (Jul 2019 CPU)NessusMisc.
critical
125419Fedora 30 : mod_http2 (2019-08e57d15fd)NessusFedora Local Security Checks
medium
124541Fedora 30 : httpd (2019-cf7695b470)NessusFedora Local Security Checks
high
124264openSUSE Security Update : apache2 (openSUSE-2019-1258)NessusSuSE Local Security Checks
high
124125Amazon Linux 2 : httpd (ALAS-2019-1189)NessusAmazon Linux Local Security Checks
high
124102openSUSE Security Update : apache2 (openSUSE-2019-1209)NessusSuSE Local Security Checks
high
124017openSUSE Security Update : apache2 (openSUSE-2019-1190)NessusSuSE Local Security Checks
high
123958Amazon Linux AMI : httpd24 (ALAS-2019-1189)NessusAmazon Linux Local Security Checks
high
98530Apache 2.4.x < 2.4.39 Multiple VulnerabilitiesWeb Application ScanningComponent Vulnerability
high
700509Apache HTTP Server < 2.4.39 Multiple VulnerabilitiesNessus Network MonitorWeb Servers
high
123787Ubuntu 14.04 LTS / 16.04 LTS / 18.04 LTS / 18.10 : apache2 vulnerabilities (USN-3937-1)NessusUbuntu Local Security Checks
high
123785SUSE SLES12 Security Update : apache2 (SUSE-SU-2019:0878-1)NessusSuSE Local Security Checks
high
123782SUSE SLED15 / SLES15 Security Update : apache2 (SUSE-SU-2019:0873-1)NessusSuSE Local Security Checks
high
123691Debian DSA-4422-1 : apache2 - security updateNessusDebian Local Security Checks
high
123644FreeBSD : Apache -- Multiple vulnerabilities (cf2105c6-551b-11e9-b95c-b499baebfeaf)NessusFreeBSD Local Security Checks
high
123642Apache 2.4.x < 2.4.39 Multiple VulnerabilitiesNessusWeb Servers
high