CVE-2019-10081
Last modified
CVE-2019-10081 is a vulnerability of currently unknown severity. HTTP/2 (2.4.20 through 2.4.39) very early pushes, for example configured with "H2PushResource", could lead to an overwrite of memory in the pushing request's pool, leading to crashes. The memory copied is that of the configured push link header values, not data supplied by the client.. EPSS estimates a 14.56% chance of exploitation in the next 30 days.
Description
HTTP/2 (2.4.20 through 2.4.39) very early pushes, for example configured with "H2PushResource", could lead to an overwrite of memory in the pushing request's pool, leading to crashes. The memory copied is that of the configured push link header values, not data supplied by the client.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Http Server | >= 2.4.20, <= 2.4.39 |
| Debian | Debian Linux | 9.0 |
| Debian | Debian Linux | 10.0 |
References
- https://httpd.apache.org/security/vulnerabilities_24.htmlExploit, Vendor Advisory
- https://seclists.org/bugtraq/2019/Aug/47Third Party Advisory
- https://www.debian.org/security/2019/dsa-4509Third Party Advisory
- https://httpd.apache.org/security/vulnerabilities_24.htmlExploit, Vendor Advisory
- https://seclists.org/bugtraq/2019/Aug/47Third Party Advisory
- https://www.debian.org/security/2019/dsa-4509Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-10081?
How severe is CVE-2019-10081?
How do I fix CVE-2019-10081?
Are you affected by CVE-2019-10081?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
