CVE-2019-0196
11.06.2019, 22:29
A vulnerability was found in Apache HTTP Server 2.4.17 to 2.4.38. Using fuzzed network input, the http/2 request handling could be made to access freed memory in string comparison when determining the method of a request and thus process the request incorrectly.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| apache | http_server | 2.4.17 ≤ 𝑥 ≤ 2.4.38 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 18.10 |
| debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache2 |
| ||||||||||||||||||||||
| apache2-devel |
| ||||||||||||||||||||||
| apache2-doc |
| ||||||||||||||||||||||
| apache2-example-pages |
| ||||||||||||||||||||||
| apache2-prefork |
| ||||||||||||||||||||||
| apache2-utils |
| ||||||||||||||||||||||
| apache2-worker |
|
Common Weakness Enumeration
References