CVE-2019-12412
published 2020-11-19CVE-2019-12412: A flaw in the libapreq2 v2.07 to v2.13 multipart parser can deference a null pointer leading to a process crash. A remote attacker could send a request causing…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.94%
89.2th percentile
A flaw in the libapreq2 v2.07 to v2.13 multipart parser can deference a null pointer leading to a process crash. A remote attacker could send a request causing a process crash which could lead to a denial of service attack.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | libapreq2 | — | — |
| apache | libapreq2 | >= 0 < 2.13-6 | 2.13-6 |
| apache | libapreq2 | >= 0 < 2.13-6 | 2.13-6 |
| apache | libapreq2 | >= 0 < 2.13-6 | 2.13-6 |
| apache | libapreq2 | 2.07 – 2.13 | — |
| debian | libapreq2 | < libapreq2 2.13-6 (bullseye) | libapreq2 2.13-6 (bullseye) |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-239h-283c-gxph: A flaw in the libapreq2 v2
ghsa_unreviewed·2022-05-24
CVE-2019-12412 [HIGH] CWE-476 GHSA-239h-283c-gxph: A flaw in the libapreq2 v2
A flaw in the libapreq2 v2.07 to v2.13 multipart parser can deference a null pointer leading to a process crash. A remote attacker could send a request causing a process crash which could lead to a denial of service attack.
OSV
CVE-2019-12412: A flaw in the libapreq2 v2
osv·2020-11-19·CVSS 7.5
CVE-2019-12412 [HIGH] CVE-2019-12412: A flaw in the libapreq2 v2
A flaw in the libapreq2 v2.07 to v2.13 multipart parser can deference a null pointer leading to a process crash. A remote attacker could send a request causing a process crash which could lead to a denial of service attack.
Ubuntu
libapreq2 vulnerability
vendor_ubuntu·2021-08-17
CVE-2019-12412 libapreq2 vulnerability
Title: libapreq2 vulnerability
Summary: libapreq2 could be made to crash if it received specially crafted
input.
It was discovered that libapreq2 did not properly sanitize the Content-Type
field in certain crafted HTTP requests. An attacker could possibly use the
vulnerability to cause libapreq2 to crash.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
libapreq2 vulnerabilities
vendor_ubuntu·2020-09-30
CVE-2019-12412 libapreq2 vulnerabilities
Title: libapreq2 vulnerabilities
Summary: libapreq2 could be made to crash if it received specially crafted network
traffic.
It was discovered that libapreq2 did not properly sanitize the Content-Type
field in certain, crafted HTTP requests. An attacker could use this
vulnerability to cause libapreq2 to crash.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2019-12412: libapreq2 - A flaw in the libapreq2 v2.07 to v2.13 multipart parser can deference a null poi...
vendor_debian·2019·CVSS 7.5
CVE-2019-12412 [HIGH] CVE-2019-12412: libapreq2 - A flaw in the libapreq2 v2.07 to v2.13 multipart parser can deference a null poi...
A flaw in the libapreq2 v2.07 to v2.13 multipart parser can deference a null pointer leading to a process crash. A remote attacker could send a request causing a process crash which could lead to a denial of service attack.
Scope: local
bullseye: resolved (fixed in 2.13-6)
forky: resolved (fixed in 2.13-6)
sid: resolved (fixed in 2.13-6)
trixie: resolved (fixed in 2.13-6)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-12412 libapreq2: libapreq: null pointer dereference in create_multipart_context() [fedora-all]
bugzilla·2019-10-04·CVSS 7.5
CVE-2019-12412 [HIGH] CVE-2019-12412 libapreq2: libapreq: null pointer dereference in create_multipart_context() [fedora-all]
CVE-2019-12412 libapreq2: libapreq: null pointer dereference in create_multipart_context() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects m
Bugzilla
CVE-2019-12412 libapreq2: libapreq: null pointer dereference in create_multipart_context() [epel-all]
bugzilla·2019-10-04·CVSS 7.5
CVE-2019-12412 [HIGH] CVE-2019-12412 libapreq2: libapreq: null pointer dereference in create_multipart_context() [epel-all]
CVE-2019-12412 libapreq2: libapreq: null pointer dereference in create_multipart_context() [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multi
Bugzilla
CVE-2019-12412 libapreq: null pointer dereference in create_multipart_context()
bugzilla·2019-10-04·CVSS 7.5
CVE-2019-12412 [HIGH] CVE-2019-12412 libapreq: null pointer dereference in create_multipart_context()
CVE-2019-12412 libapreq: null pointer dereference in create_multipart_context()
A vulnerability was found in libapreq2 through 2.13 where multipart parser can be made dereference the null pointer
by issuing a simple CURL command.
Reference:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=939937
Discussion:
Created libapreq2 tracking bugs for this issue:
Affects: epel-all [bug 1758454]
Affects: fedora-all [bug 1758453]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.
https://bugs.debian.org/939937https://lists.apache.org/thread.html/rce5814279a615d4a17c870a3c5b77f57975874d382ffee0b73b7f9da%40%3Cmodperl.perl.apache.org%3Ehttps://bugs.debian.org/939937https://lists.apache.org/thread.html/rce5814279a615d4a17c870a3c5b77f57975874d382ffee0b73b7f9da%40%3Cmodperl.perl.apache.org%3E
2020-11-19
Published