A flaw in the libapreq2 v2.07 to v2.13 multipart parser can deference a null pointer leading to a process crash. A remote attacker could send a request causing a process crash which could lead to a denial of service attack.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | Upgrade libapreq2 | Nov 23, 2019 | Nov 19, 2019 |
| Debian | — | Upgrade libapreq2 | Oct 4, 2019 | Oct 4, 2019 |
| Ubuntu | — | Upgrade libapreq2-3Upgrade libapache2-request-perlUpgrade libapache2-request-perl (Ubuntu Pro)Upgrade libapreq2-devUpgrade libapache2-mod-apreq2Upgrade libapreq2-3 (Ubuntu Pro)Upgrade libapache2-mod-apreq2 (Ubuntu Pro) | Oct 1, 2020 | Nov 22, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub