While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The vulnerability was recently introduced in version 2.4.49. No exploit is known to the project.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade apache2 | Aug 22, 2024 | Oct 5, 2021 |
| Amazon Linux Ami 2 | — | Upgrade httpd-debuginfoUpgrade httpd-develUpgrade httpdUpgrade mod_sessionUpgrade mod_sslUpgrade httpd-manualUpgrade mod_proxy_htmlUpgrade mod_mdUpgrade httpd-toolsUpgrade httpd-filesystemUpgrade mod_ldap | Oct 18, 2021 | Oct 18, 2021 |
| Amazon_linux | — | Upgrade httpd24 | Oct 16, 2021 | Oct 5, 2021 |
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Dec 22, 2021 | Oct 5, 2021 |
| Check Point Gaia | — | Upgrade to supported version Check Point Gaia. | Feb 25, 2026 | Oct 27, 2021 |
| Debian | — | Upgrade apache2 | Jul 30, 2024 | Oct 5, 2021 |
| Freebsd | — | Upgrade apache24 | Nov 4, 2022 | Oct 5, 2021 |
| Gentoo Linux | — | Upgrade app-admin/apache-tools.Upgrade www-servers/apache. | Aug 16, 2022 | Oct 5, 2021 |
| Oracle Solaris | — | Upgrade web/server/apache-24/module/apache-ssl-fips-140 to version 2.4.51-11.4.38.0.1.101.6 on Solaris 11.4Upgrade web/server/apache-24/module/apache-dbd to version 2.4.51-11.4.38.0.1.101.6 on Solaris 11.4Upgrade web/server/apache-24/module/apache-gss to version 2.4.51-11.4.38.0.1.101.6 on Solaris 11.4Upgrade web/server/apache-24/module/apache-ldap to version 2.4.51-11.4.38.0.1.101.6 on Solaris 11.4Upgrade web/server/apache-24/module/apache-ssl to version 2.4.51-11.4.38.0.1.101.6 on Solaris 11.4Upgrade web/server/apache-24/module/apache-lua to version 2.4.51-11.4.38.0.1.101.6 on Solaris 11.4Upgrade web/server/apache-24 to version 2.4.51-11.4.38.0.1.101.6 on Solaris 11.4 | Nov 17, 2021 | Nov 17, 2021 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Oct 5, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub