cbcvebase.
CVE-2020-35452
published 2021-06-10

CVE-2020-35452: Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow…

PriorityP260high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
53.19%
98.9th percentile
Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP Server team could create one, though some particular compiler and/or compilation option might make it possible, with limited consequences anyway due to the size (a single byte) and the value (zero byte) of the overflow

Affected

42 ranges· showing 25
VendorProductVersion rangeFixed in
apachehttp_server2.4.0 – 2.4.46
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is triggered by a specially crafted Digest nonce sent to mod_auth_digest; monitor for malformed/oversized Digest nonce values in Authorization headers targeting Apache HTTP Server 2.4.0–2.4.46.
  • Only Apache HTTP Server instances with mod_auth_digest loaded/enabled are affected; scope detection and patching efforts to those configurations.
  • The overflow is a single zero (null) byte beyond the stack buffer; a crash of the httpd worker process (SIGSEGV or similar) following a Digest authentication request may indicate exploitation attempts.
  • ·Only Apache HTTP Server versions 2.4.0 through 2.4.46 are vulnerable; 2.4.48+ contains the fix. Verify the running version before treating an instance as affected.
  • ·Exploitability is highly compiler/compilation-option dependent; the overflow is a single null byte and upstream considers it non-exploitable in most conditions, limiting real-world impact.
  • ·Red Hat Enterprise Linux 9 is listed as Not Affected; tailor detection/patching scope accordingly across RHEL versions.

CVSS provenance

nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian7.3HIGH
vendor_msrc7.3HIGH
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.