CVE-2020-13950
10.06.2021, 07:15
Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using both Content-Length and Transfer-Encoding headers, leading to a Denial of ServiceEnginsight
| Vendor | Product | Version |
|---|---|---|
| apache | http_server | 2.4.41 ≤ 𝑥 ≤ 2.4.46 |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
| oracle | enterprise_manager_ops_center | 12.4.0.0 |
| oracle | instantis_enterprisetrack | 17.1 |
| oracle | instantis_enterprisetrack | 17.2 |
| oracle | instantis_enterprisetrack | 17.3 |
| oracle | zfs_storage_appliance_kit | 8.8 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References