CVE-2019-0197

Severity
4.2MEDIUM
EPSS
2.2%
top 15.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 24

Description

A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http: host or H2Upgrade was enabled for h2 on a https: host, an Upgrade request from http/1.1 to http/2 that was not the first request on a connection could lead to a misconfiguration and crash. Server that never enabled the h2 protocol or that only enabled it for https: and did not set "H2Upgrade on" are unaffected by this issue.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:LExploitability: 1.6 | Impact: 2.5

Affected Packages12 packages

NVDapache/http_server2.4.342.4.38
NVDoracle/http_server12.2.1.3.0
Debianapache2< 2.4.38-3+3
Ubuntuapache2< 2.4.18-2ubuntu3.12+1

Also affects: Fedora 30, Ubuntu Linux 16.04, 18.04, 19.04

Patches

🔴Vulnerability Details

5
GHSA
GHSA-g33m-gfwr-29g4: A vulnerability was found in Apache HTTP Server 22022-05-24
OSV
apache2 regression2019-09-17
OSV
apache2 vulnerabilities2019-08-29
OSV
CVE-2019-0197: A vulnerability was found in Apache HTTP Server 22019-06-11
CVEList
CVE-2019-0197: A vulnerability was found in Apache HTTP Server 22019-06-11

📋Vendor Advisories

3
Ubuntu
Apache HTTP Server vulnerabilities2019-08-29
Red Hat
httpd: mod_http2: possible crash on late upgrade2019-02-01
Debian
CVE-2019-0197: apache2 - A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 wa...2019

💬Community

1
Bugzilla
CVE-2019-0197 httpd: mod_http2: possible crash on late upgrade2019-04-02
CVE-2019-0197 (MEDIUM CVSS 4.2) | A vulnerability was found in Apache | cvebase.io