While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The vulnerability was recently introduced in version 2.4.49. No exploit is known to the project.
2021-10-05T09:15:07.427
2024-11-21T06:26:20.867
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | http_server | 2.4.49 | Yes |
Operating System | fedoraproject | fedora | 34 | Yes |
Operating System | fedoraproject | fedora | 35 | Yes |
Application | oracle | instantis_enterprisetrack | 17.1 | Yes |
Application | oracle | instantis_enterprisetrack | 17.2 | Yes |
Application | oracle | instantis_enterprisetrack | 17.3 | Yes |
Application | netapp | cloud_backup | - | Yes |