CVE-2019-10082Use After Free in Apache Http Server

CWE-416Use After Free19 documents10 sources
Severity
9.1CRITICALNVD
EPSS
47.9%
top 2.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 26
Latest updateJul 15

Description

In Apache HTTP Server 2.4.18-2.4.39, using fuzzed network input, the http/2 session handling could be made to read memory after being freed, during connection shutdown.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HExploitability: 3.9 | Impact: 5.2

Affected Packages7 packages

NVDapache/http_server2.4.182.4.39
NVDoracle/http_server12.2.1.3.0, 12.2.1.4.0+1
NVDoracle/enterprise_manager_ops_center12.3.3, 12.4.0, 12.4.0.0+2

Patches

🔴Vulnerability Details

3
GHSA
GHSA-28c2-r3qq-82vj: In Apache HTTP Server 22022-05-24
OSV
CVE-2019-10082: In Apache HTTP Server 22019-09-26
CVEList
CVE-2019-10082: In Apache HTTP Server 22019-09-26

📋Vendor Advisories

5
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: SSL Module (Apache HTTP Server) — CVE-2019-100822022-07-15
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (Apache HTTP Server) — CVE-2019-100822020-04-15
Ubuntu
Apache HTTP Server vulnerabilities2019-08-29
Red Hat
httpd: read-after-free in h2 connection shutdown2019-08-14
Debian
CVE-2019-10082: apache2 - In Apache HTTP Server 2.4.18-2.4.39, using fuzzed network input, the http/2 sess...2019

💬Community

9
HackerOne
mod_http2, read-after-free in h2 connection shutdown (CVE-2019-10082)2019-10-15
Bugzilla
CVE-2019-10082 nghttp2: httpd: read-after-free in h2 connection shutdown [fedora-all]2019-08-21
Bugzilla
CVE-2019-10082 httpd: read-after-free in h2 connection shutdown2019-08-21
Bugzilla
CVE-2019-10082 httpd: read-after-free in h2 connection shutdown [fedora-all]2019-08-21
Bugzilla
CVE-2019-10082 nghttp2: httpd: read-after-free in h2 connection shutdown [epel-all]2019-08-21
CVE-2019-10082 — Use After Free in Apache Http Server | cvebase