CVE-2020-35452
published 2021-06-10CVE-2020-35452: Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow…
PriorityP260high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
53.19%
98.9th percentile
Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP Server team could create one, though some particular compiler and/or compilation option might make it possible, with limited consequences anyway due to the size (a single byte) and the value (zero byte) of the overflow
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | 2.4.0 – 2.4.46 | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is triggered by a specially crafted Digest nonce sent to mod_auth_digest; monitor for malformed/oversized Digest nonce values in Authorization headers targeting Apache HTTP Server 2.4.0–2.4.46. ↗
- →Only Apache HTTP Server instances with mod_auth_digest loaded/enabled are affected; scope detection and patching efforts to those configurations. ↗
- →The overflow is a single zero (null) byte beyond the stack buffer; a crash of the httpd worker process (SIGSEGV or similar) following a Digest authentication request may indicate exploitation attempts. ↗
- ·Only Apache HTTP Server versions 2.4.0 through 2.4.46 are vulnerable; 2.4.48+ contains the fix. Verify the running version before treating an instance as affected. ↗
- ·Exploitability is highly compiler/compilation-option dependent; the overflow is a single null byte and upstream considers it non-exploitable in most conditions, limiting real-world impact. ↗
- ·Red Hat Enterprise Linux 9 is listed as Not Affected; tailor detection/patching scope accordingly across RHEL versions. ↗
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian7.3HIGH
vendor_msrc7.3HIGH
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2021-06-21·CVSS 7.5
CVE-2021-26691 [HIGH] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
Marc Stern discovered that the Apache mod_proxy_http module incorrectly
handled certain requests. A remote attacker could possibly use this issue
to cause Apache to crash, resulting in a denial of service. This issue only
affected Ubuntu 20.04 LTS, Ubuntu 20.10, and Ubuntu 21.04. (CVE-2020-13950)
Antonio Morales discovered that the Apache mod_auth_digest module
incorrectly handled certain Digest nonces. A remote attacker could possibly
use this issue to cause Apache to crash, resulting in a denial of service.
(CVE-2020-35452)
Antonio Morales discovered that the Apache mod_session module incorrectly
handled certain Cookie headers. A remote attacker could possibly use this
issue t
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2021-06-21·CVSS 7.3
CVE-2021-26691 [HIGH] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
USN-4994-1 fixed several vulnerabilities in Apache. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
Antonio Morales discovered that the Apache mod_auth_digest module
incorrectly handled certain Digest nonces. A remote attacker could possibly
use this issue to cause Apache to crash, resulting in a denial of service.
(CVE-2020-35452)
Antonio Morales discovered that the Apache mod_session module incorrectly
handled certain Cookie headers. A remote attacker could possibly use this
issue to cause Apache to crash, resulting in a denial of service.
(CVE-2021-26690)
Christophe Jaillet discovered that the Apache mod_se
Microsoft
mod_auth_digest possible stack overflow by one nul byte
vendor_msrc·2021-06-08·CVSS 7.3
CVE-2020-35452 [HIGH] CWE-787 mod_auth_digest possible stack overflow by one nul byte
mod_auth_digest possible stack overflow by one nul byte
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
apache: apache
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://lea
Red Hat
httpd: Single zero byte stack overflow in mod_auth_digest
vendor_redhat·2021-06-04·CVSS 7.3
CVE-2020-35452 [HIGH] CWE-119 httpd: Single zero byte stack overflow in mod_auth_digest
httpd: Single zero byte stack overflow in mod_auth_digest
Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP Server team could create one, though some particular compiler and/or compilation option might make it possible, with limited consequences anyway due to the size (a single byte) and the value (zero byte) of the overflow
A flaw was found in Apache httpd. The mod_auth_digest has a single zero byte stack overflow. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Statement: This is a one byte overflow and as per upstream it should be non-exploitable in most condtions.
Miti
Debian
CVE-2020-35452: apache2 - Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can...
vendor_debian·2020·CVSS 7.3
CVE-2020-35452 [HIGH] CVE-2020-35452: apache2 - Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can...
Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP Server team could create one, though some particular compiler and/or compilation option might make it possible, with limited consequences anyway due to the size (a single byte) and the value (zero byte) of the overflow
Scope: local
bookworm: resolved (fixed in 2.4.46-6)
bullseye: resolved (fixed in 2.4.46-6)
forky: resolved (fixed in 2.4.46-6)
sid: resolved (fixed in 2.4.46-6)
trixie: resolved (fixed in 2.4.46-6)
GHSA
GHSA-77mj-xh9q-fm9j: Apache HTTP Server versions 2
ghsa_unreviewed·2022-05-24
CVE-2020-35452 [HIGH] CWE-787 GHSA-77mj-xh9q-fm9j: Apache HTTP Server versions 2
Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP Server team could create one, though some particular compiler and/or compilation option might make it possible, with limited consequences anyway due to the size (a single byte) and the value (zero byte) of the overflow
OSV
apache2 vulnerabilities
osv·2021-06-21·CVSS 7.3
CVE-2020-35452 [HIGH] apache2 vulnerabilities
apache2 vulnerabilities
USN-4994-1 fixed several vulnerabilities in Apache. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
Antonio Morales discovered that the Apache mod_auth_digest module
incorrectly handled certain Digest nonces. A remote attacker could possibly
use this issue to cause Apache to crash, resulting in a denial of service.
(CVE-2020-35452)
Antonio Morales discovered that the Apache mod_session module incorrectly
handled certain Cookie headers. A remote attacker could possibly use this
issue to cause Apache to crash, resulting in a denial of service.
(CVE-2021-26690)
Christophe Jaillet discovered that the Apache mod_session module
incorrectly handled certain SessionHeader values. A remote attacker could
OSV
apache2 vulnerabilities
osv·2021-06-21·CVSS 7.5
CVE-2020-13950 [HIGH] apache2 vulnerabilities
apache2 vulnerabilities
Marc Stern discovered that the Apache mod_proxy_http module incorrectly
handled certain requests. A remote attacker could possibly use this issue
to cause Apache to crash, resulting in a denial of service. This issue only
affected Ubuntu 20.04 LTS, Ubuntu 20.10, and Ubuntu 21.04. (CVE-2020-13950)
Antonio Morales discovered that the Apache mod_auth_digest module
incorrectly handled certain Digest nonces. A remote attacker could possibly
use this issue to cause Apache to crash, resulting in a denial of service.
(CVE-2020-35452)
Antonio Morales discovered that the Apache mod_session module incorrectly
handled certain Cookie headers. A remote attacker could possibly use this
issue to cause Apache to crash, resulting in a denial of service.
(CVE-2021-26690)
Christoph
OSV
CVE-2020-35452: Apache HTTP Server versions 2
osv·2021-06-10·CVSS 7.3
CVE-2020-35452 [HIGH] CVE-2020-35452: Apache HTTP Server versions 2
Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP Server team could create one, though some particular compiler and/or compilation option might make it possible, with limited consequences anyway due to the size (a single byte) and the value (zero byte) of the overflow
No detection rules found.
No public exploits indexed.
http://httpd.apache.org/security/vulnerabilities_24.htmlhttp://www.openwall.com/lists/oss-security/2021/06/10/5https://lists.apache.org/thread.html/r7f2b70b621651548f4b6f027552f1dd91705d7111bb5d15cda0a68dd%40%3Cdev.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rccb1b8225583a48c6360edc7a93cc97ae8b0215791e455dc607e7602%40%3Cannounce.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re026d3da9d7824bd93b9f871c0fdda978d960c7e62d8c43cba8d0bf3%40%3Ccvs.httpd.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/07/msg00006.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7TJOHX7RHWD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3HDQK4VP45R/https://security.gentoo.org/glsa/202107-38https://security.netapp.com/advisory/ntap-20210702-0001/https://www.debian.org/security/2021/dsa-4937https://www.oracle.com/security-alerts/cpuoct2021.htmlhttp://httpd.apache.org/security/vulnerabilities_24.htmlhttp://www.openwall.com/lists/oss-security/2021/06/10/5https://lists.apache.org/thread.html/r7f2b70b621651548f4b6f027552f1dd91705d7111bb5d15cda0a68dd%40%3Cdev.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rccb1b8225583a48c6360edc7a93cc97ae8b0215791e455dc607e7602%40%3Cannounce.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re026d3da9d7824bd93b9f871c0fdda978d960c7e62d8c43cba8d0bf3%40%3Ccvs.httpd.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/07/msg00006.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7TJOHX7RHWD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3HDQK4VP45R/https://security.gentoo.org/glsa/202107-38https://security.netapp.com/advisory/ntap-20210702-0001/https://www.debian.org/security/2021/dsa-4937https://www.oracle.com/security-alerts/cpuoct2021.html
2021-06-10
Published