CVE-2019-12412

Severity
7.5HIGH
EPSS
2.4%
top 14.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 19
Latest updateMay 24

Description

A flaw in the libapreq2 v2.07 to v2.13 multipart parser can deference a null pointer leading to a process crash. A remote attacker could send a request causing a process crash which could lead to a denial of service attack.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

Debianlibapreq2< 2.13-6+2
NVDapache/libapreq22.072.13
CVEListV5libapreq22.07 to 2.13

🔴Vulnerability Details

3
GHSA
GHSA-239h-283c-gxph: A flaw in the libapreq2 v22022-05-24
OSV
CVE-2019-12412: A flaw in the libapreq2 v22020-11-19
CVEList
CVE-2019-12412: A flaw in the libapreq2 v22020-11-18

📋Vendor Advisories

3
Ubuntu
libapreq2 vulnerability2021-08-17
Ubuntu
libapreq2 vulnerabilities2020-09-30
Debian
CVE-2019-12412: libapreq2 - A flaw in the libapreq2 v2.07 to v2.13 multipart parser can deference a null poi...2019

💬Community

3
Bugzilla
CVE-2019-12412 libapreq2: libapreq: null pointer dereference in create_multipart_context() [fedora-all]2019-10-04
Bugzilla
CVE-2019-12412 libapreq2: libapreq: null pointer dereference in create_multipart_context() [epel-all]2019-10-04
Bugzilla
CVE-2019-12412 libapreq: null pointer dereference in create_multipart_context()2019-10-04
CVE-2019-12412 (HIGH CVSS 7.5) | A flaw in the libapreq2 v2.07 to v2 | cvebase.io