Back

HIGH

mod_auth_digest possible stack overflow by one nul byte

Published Jun 10, 2021

Description

Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP Server team could create one, though some particular compiler and/or compilation option might make it possible, with limited consequences anyway due to the size (a single byte) and the value (zero byte) of the overflow

Affected products

Remediation

Red Hat statement

This is a one byte overflow and as per upstream it should be non-exploitable in most condtions.

Red Hat mitigation

Only configurations which use mod_auth_digest are affected by this flaw. Also as per upstream this flaw is not exploitable in most conditions, so there should really be no impact of this flaw.

Metrics

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Jun 10, 2021
Updated Aug 4, 2024
Reserved Dec 14, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jun 4, 2021