Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia: 2019-0407 Moderate: Apache Memory Overwrite and DoS Threats

mageia
Calendar Grey December 25, 2019
Dist Mageia Esm H88
Enhanced Apache updates address multiple vulnerabilities such as denial of service attacks, memory corruption, and cross-site scripting threats.
The updated packages fix security vulnerabilities: Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service

Summary

The updated packages fix security vulnerabilities:
Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The attacker then sends a stream of requests for a large response object. Depending on how the servers queue the responses, this can consume excess memory, CPU, or both. (CVE-2019-9517)
HTTP/2 (2.4.20 through 2.4.39) very early pushes, for example configured with "H2PushResource", could lead to an overwrite of memory in the pushing request's pool, leading to crashes. The memory copied is that of the configured push link header values, not data supplied by the client. (CVE-2019-10081)
In Apache HTTP Server 2.4.18-2.4.39, using fuzzed network input, the http/2 session handling could be made to read memory after being freed, d...

Read the Full Advisory

References

- https://bugs.mageia.org/show_bug.cgi?id=25316

- - https://httpd.apache.org/security/vulnerabilities_24.html

- https://lists.debian.org/debian-security-announce/2019/msg00157.html

- - https://www.cve.org/CVERecord?id=CVE-2019-9517

- https://www.cve.org/CVERecord?id=CVE-2019-10081

- https://www.cve.org/CVERecord?id=CVE-2019-10082

- https://www.cve.org/CVERecord?id=CVE-2019-10092

- https://www.cve.org/CVERecord?id=CVE-2019-10097

- https://www.cve.org/CVERecord?id=CVE-2019-10098

Resolution

SRPMS

- 7/core/apache-2.4.41-1.2.mga7

Publication date: 25 Dec 2019
URL: https://advisories.mageia.org/MGASA-2019-0407.html
Type: security
CVE: CVE-2019-9517, CVE-2019-10081, CVE-2019-10082, CVE-2019-10092, CVE-2019-10097, CVE-2019-10098

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here