cbcvebase.
CVE-2019-0190
published 2019-01-30

CVE-2019-0190: A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause mod_ssl to enter a…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause mod_ssl to enter a loop leading to a denial of service. This bug can be only triggered with Apache HTTP Server version 2.4.37 when using OpenSSL version 1.1.1 or later, due to an interaction in changes to handling of renegotiation attempts.

Affected

12 ranges
VendorProductVersion rangeFixed in
apachehttp_server
apachehttpd
apache_software_foundationapache_http_server
debianapache2< apache2 2.4.38-1 (bookworm)apache2 2.4.38-1 (bookworm)
oracleenterprise_manager_ops_center
oraclehospitality_guest_access
oraclehospitality_guest_access
oracleinstantis_enterprisetrack
oracleinstantis_enterprisetrack
oracleinstantis_enterprisetrack
oracleretail_xstore_point_of_service
oracleretail_xstore_point_of_service

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vulncheck7.5HIGH