FreeBSD : Apache httpd -- Multiple vulnerabilities (76700d2f-d959-11ea-b53c-d4c9ef517024)

critical Nessus Plugin ID 139436

Language:

Synopsis

The remote FreeBSD host is missing one or more security-related updates.

Description

The Apache httpd projec reports :

- mod_http2: Important: Push Diary Crash on Specifically Crafted HTTP/2 Header (CVE-2020-9490) A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards.

- mod_proxy_uwsgi: Moderate: mod_proxy_uwsgi buffer overflow (CVE-2020-11984) info disclosure and possible RCE

- mod_http2: Moderate: Push Diary Crash on Specifically Crafted HTTP/2 Header (CVE-2020-11993) When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools.

Solution

Update the affected packages.

See Also

https://downloads.apache.org/httpd/CHANGES_2.4.46

https://httpd.apache.org/security/vulnerabilities_24.html

http://www.nessus.org/u?18a40877

Plugin Details

Severity: Critical

ID: 139436

File Name: freebsd_pkg_76700d2fd95911eab53cd4c9ef517024.nasl

Version: 1.8

Type: local

Published: 8/10/2020

Updated: 2/26/2024

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2020-11984

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:apache24, p-cpe:/a:freebsd:freebsd:mod_http2, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/8/2020

Vulnerability Publication Date: 8/7/2020

Reference Information

CVE: CVE-2020-11984, CVE-2020-11993, CVE-2020-9490

IAVA: 2020-A-0376-S