CVE-2020-11993
07.08.2020, 16:15
Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above "info" will mitigate this vulnerability for unpatched servers.
Vendor | Product | Version |
---|---|---|
apache | http_server | 2.4.20 ≤ 𝑥 < 2.4.44 |
netapp | clustered_data_ontap | - |
canonical | ubuntu_linux | 16.04 |
canonical | ubuntu_linux | 18.04 |
canonical | ubuntu_linux | 20.04 |
opensuse | leap | 15.1 |
opensuse | leap | 15.2 |
debian | debian_linux | 10.0 |
oracle | communications_element_manager | 8.2.0 ≤ 𝑥 ≤ 8.2.2 |
oracle | communications_session_report_manager | 8.2.0 ≤ 𝑥 ≤ 8.2.2 |
oracle | communications_session_route_manager | 8.2.0 ≤ 𝑥 ≤ 8.2.2 |
oracle | enterprise_manager_ops_center | 12.4.0.0 |
oracle | hyperion_infrastructure_technology | 11.1.2.4 |
oracle | instantis_enterprisetrack | 17.1 |
oracle | instantis_enterprisetrack | 17.2 |
oracle | instantis_enterprisetrack | 17.3 |
oracle | zfs_storage_appliance_kit | 8.8 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References