CVE-2019-0197

MEDIUM

Apache HTTP Server 2.4.34-2.4.38 - Denial of Service via HTTP/2 Upgrade Request

Title source: llm
STIX 2.1

Description

A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http: host or H2Upgrade was enabled for h2 on a https: host, an Upgrade request from http/1.1 to http/2 that was not the first request on a connection could lead to a misconfiguration and crash. Server that never enabled the h2 protocol or that only enabled it for https: and did not set "H2Upgrade on" are unaffected by this issue.

References (30)

Core 30
Core References
Vendor Advisory x_refsource_confirm
https://httpd.apache.org/security/vulnerabilities_24.html
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2019/04/02/2
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/107665
Mailing List, Patch, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00051.html
Mailing List, Patch, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00061.html
Mailing List, Patch, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00084.html
Third Party Advisory x_refsource_confirm
https://support.f5.com/csp/article/K44591505
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20190617-0002/
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4113-1/
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:3933
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:3935
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:3932
Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuapr2020.html

Scores

CVSS v3 4.2
EPSS 0.0874
EPSS Percentile 94.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L

Details

CWE
CWE-444
Status published
Products (24)
apache/http_server 2.4.34 - 2.4.38
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 18.04
canonical/ubuntu_linux 19.04
fedoraproject/fedora 30
opensuse/leap 15.0
opensuse/leap 42.3
oracle/communications_session_report_manager 8.0.0
oracle/communications_session_report_manager 8.1.0
oracle/communications_session_report_manager 8.1.1
... and 14 more
Published Jun 11, 2019
Tracked Since Feb 18, 2026