Allele Security Alert
ASA-2019-00514
Identifier(s)
ASA-2019-00514, CVE-2019-10082
Title
mod_http2, read-after-free in h2 connection shutdown
Vendor(s)
The Apache Software Foundation
Product(s)
Apache HTTP Server
Affected version(s)
Apache HTTP Server versions 2.4.18 to 2.4.39
Fixed version(s)
Apache HTTP Server version 2.4.41
Proof of concept
Unknown
Description
Using fuzzed network input, the http/2 session handling could be made to read memory after being freed, during connection shutdown.
Technical details
Unknown
Credits
Craig Young (Tripwire VERT)
Reference(s)
httpd 2.4 vulnerabilities – The Apache HTTP Server Project
https://httpd.apache.org/security/vulnerabilities_24.html
CVE-2019-10082: mod_http2, read-after-free in h2 connection shutdown
https://seclists.org/oss-sec/2019/q3/138
Apache HTTP Server 2.4.41 Released
https://www.apache.org/dist/httpd/Announcement2.4.html
CVE-2019-10082
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10082
CVE-2019-10082
https://nvd.nist.gov/vuln/detail/CVE-2019-10082
If there is any error in this alert or you wish a comprehensive analysis, let us know.
Last modified: August 20, 2019