httpd: memory corruption on early pushes
Published Aug 15, 2019
7.5
HIGHCVSS 3.0
EPSS 14.56%
Description
HTTP/2 (2.4.20 through 2.4.39) very early pushes, for example configured with "H2PushResource", could lead to an overwrite of memory in the pushing request's pool, leading to crashes. The memory copied is that of the configured push link header values, not data supplied by the client.
Affected products
- Vendor n/a Product Apache HTTP Server Defaultunknown
Affected
- 2.4.20 to 2.4.39
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Apache HTTP Server | unknown | Affected
|
Configuration 1
- ≥ 2.4.20 · ≤ 2.4.39
Configuration 2
- 9.0
- 10.0
No data.
JBoss Core Services Apache HTTP Server 2.4.37 SP2
httpd
Fixed · RHSA-2020:1336
JBoss Core Services on RHEL 6
jbcs-httpd24-apr-0:1.6.3-86.jbcs.el6
Fixed · RHSA-2020:1337
JBoss Core Services on RHEL 6
jbcs-httpd24-brotli-0:1.0.6-21.jbcs.el6
Fixed · RHSA-2020:1337
JBoss Core Services on RHEL 6
jbcs-httpd24-httpd-0:2.4.37-52.jbcs.el6
Fixed · RHSA-2020:1337
JBoss Core Services on RHEL 6
jbcs-httpd24-mod_cluster-native-0:1.3.12-41.Final_redhat_2.jbcs.el6
Fixed · RHSA-2020:1337
JBoss Core Services on RHEL 6
jbcs-httpd24-mod_http2-0:1.11.3-22.jbcs.el6
Fixed · RHSA-2020:1337
JBoss Core Services on RHEL 6
jbcs-httpd24-openssl-1:1.1.1c-16.jbcs.el6
Fixed · RHSA-2020:1337
JBoss Core Services on RHEL 7
jbcs-httpd24-apr-0:1.6.3-86.jbcs.el7
Fixed · RHSA-2020:1337
JBoss Core Services on RHEL 7
jbcs-httpd24-brotli-0:1.0.6-21.jbcs.el7
Fixed · RHSA-2020:1337
JBoss Core Services on RHEL 7
jbcs-httpd24-httpd-0:2.4.37-52.jbcs.el7
Fixed · RHSA-2020:1337
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_cluster-native-0:1.3.12-41.Final_redhat_2.jbcs.el7
Fixed · RHSA-2020:1337
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_http2-0:1.11.3-22.jbcs.el7
Fixed · RHSA-2020:1337
JBoss Core Services on RHEL 7
jbcs-httpd24-openssl-1:1.1.1c-16.jbcs.el7
Fixed · RHSA-2020:1337
Red Hat Enterprise Linux 8
httpd:2.4-8030020200818000036.30b713e6
Fixed · RHSA-2020:4751
Red Hat Enterprise Linux 5
httpd
Not affected
Red Hat Enterprise Linux 6
httpd
Not affected
Red Hat Enterprise Linux 7
httpd
Not affected
Red Hat JBoss Enterprise Web Server 2
httpd
Out of support scope
Red Hat JBoss Enterprise Web Server 2
httpd22
Out of support scope
Red Hat JBoss Web Server 3
httpd24
Out of support scope
Red Hat Software Collections
httpd24-httpd
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| JBoss Core Services Apache HTTP Server 2.4.37 SP2 | httpd | Fixed | RHSA-2020:1336 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-apr-0:1.6.3-86.jbcs.el6 | Fixed | RHSA-2020:1337 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-brotli-0:1.0.6-21.jbcs.el6 | Fixed | RHSA-2020:1337 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-httpd-0:2.4.37-52.jbcs.el6 | Fixed | RHSA-2020:1337 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-mod_cluster-native-0:1.3.12-41.Final_redhat_2.jbcs.el6 | Fixed | RHSA-2020:1337 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-mod_http2-0:1.11.3-22.jbcs.el6 | Fixed | RHSA-2020:1337 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-openssl-1:1.1.1c-16.jbcs.el6 | Fixed | RHSA-2020:1337 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-apr-0:1.6.3-86.jbcs.el7 | Fixed | RHSA-2020:1337 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-brotli-0:1.0.6-21.jbcs.el7 | Fixed | RHSA-2020:1337 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-httpd-0:2.4.37-52.jbcs.el7 | Fixed | RHSA-2020:1337 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_cluster-native-0:1.3.12-41.Final_redhat_2.jbcs.el7 | Fixed | RHSA-2020:1337 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_http2-0:1.11.3-22.jbcs.el7 | Fixed | RHSA-2020:1337 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-openssl-1:1.1.1c-16.jbcs.el7 | Fixed | RHSA-2020:1337 |
| Red Hat Enterprise Linux 8 | httpd:2.4-8030020200818000036.30b713e6 | Fixed | RHSA-2020:4751 |
| Red Hat Enterprise Linux 5 | httpd | Not affected | n/a |
| Red Hat Enterprise Linux 6 | httpd | Not affected | n/a |
| Red Hat Enterprise Linux 7 | httpd | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 2 | httpd | Out of support scope | n/a |
| Red Hat JBoss Enterprise Web Server 2 | httpd22 | Out of support scope | n/a |
| Red Hat JBoss Web Server 3 | httpd24 | Out of support scope | n/a |
| Red Hat Software Collections | httpd24-httpd | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
This flaw is only exploitable if Apache httpd is configured to respond to HTTP/2 requests, which is done by including "h2" or "h2c" in the "Protocols" list in a configuration file. The following command can be used to search for possible vulnerable configurations: grep -R '^\s*Protocols\>.*\<h2\>' /etc/httpd/ See https://httpd.apache.org/docs/2.4/mod/mod_http2.html
References (26)
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00004.html vendor-advisoryx_refsource_SUSE
- https://access.redhat.com/security/cve/CVE-2019-10081 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1743966 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-2135 Advisory
- https://httpd.apache.org/security/vulnerabilities_24.html x_refsource_MISCExploitVendor Advisory
- https://lists.apache.org/thread.html/r03ee478b3dda3e381fd6189366fa7af97c980d2f602846eef935277d%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r06f0d87ebb6d59ed8379633f36f72f5b1f79cadfda72ede0830b42cf%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r3c5c3104813c1c5508b55564b66546933079250a46ce50eee90b2e36%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rd2fb621142e7fa187cfe12d7137bf66e7234abcbbcd800074c84a538%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2019-10081
- https://seclists.org/bugtraq/2019/Aug/47 mailing-listx_refsource_BUGTRAQThird Party Advisory
- https://security.gentoo.org/glsa/201909-04 vendor-advisoryx_refsource_GENTOO
- https://security.netapp.com/advisory/ntap-20190905-0003/ x_refsource_CONFIRM
- https://support.f5.com/csp/article/K84341091?utm_source=f5support&%3Butm_medium=RSS x_refsource_CONFIRM
- https://usn.ubuntu.com/4113-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2019-10081
- https://www.debian.org/security/2019/dsa-4509 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.html x_refsource_MISC
- https://www.oracle.com/security-alerts/cpujul2020.html x_refsource_MISC
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html x_refsource_MISC
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data