CVE-2021-41524NULL Pointer Dereference in Software Foundation Apache Http Server

Severity
7.5HIGHNVD
EPSS
7.1%
top 8.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 5
Latest updateMay 24

Description

While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The vulnerability was recently introduced in version 2.4.49. No exploit is known to the project.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

Also affects: Fedora 34, 35

Patches

🔴Vulnerability Details

3
GHSA
GHSA-f29c-hjcq-ww2f: While fuzzing the 22022-05-24
CVEList
null pointer dereference in h2 fuzzing2021-10-05
OSV
CVE-2021-41524: While fuzzing the 22021-10-05

📋Vendor Advisories

4
Microsoft
null pointer dereference in h2 fuzzing2021-10-12
Cisco
Apache HTTP Server Vulnerabilities: October 20212021-10-07
Red Hat
httpd: NULL pointer dereference via crafted request during HTTP/2 request processing2021-10-05
Debian
CVE-2021-41524: apache2 - While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected duri...2021
CVE-2021-41524 — NULL Pointer Dereference | cvebase