Apache HTTP Server CVE-2019-0220 Remote Security Vulnerability
BID:107670
CVE-2019-220 |Info
Apache HTTP Server CVE-2019-0220 Remote Security Vulnerability
| Bugtraq ID: | 107670 |
| Class: | Design Error |
| CVE: |
CVE-2019-0220 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 01 2019 12:00AM |
| Updated: | Jun 13 2019 09:00AM |
| Credit: | Bernhard Lorenz |
| Vulnerable: |
Ubuntu Ubuntu Linux 18.10 Ubuntu Ubuntu Linux 18.04 LTS Ubuntu Ubuntu Linux 16.04 LTS Ubuntu Ubuntu Linux 14.04 LTS Redhat Software Collections for RHEL 0 Redhat Enterprise Linux 8 Redhat Enterprise Linux 7 Redhat Enterprise Linux 6 Apache Apache 2.4.38 Apache Apache 2.4.37 Apache Apache 2.4.33 Apache Apache 2.4.26 Apache Apache 2.4.25 Apache Apache 2.4.23 Apache Apache 2.4.20 Apache Apache 2.4.18 Apache Apache 2.4.17 Apache Apache 2.4.16 Apache Apache 2.4.12 Apache Apache 2.4.10 Apache Apache 2.4.4 Apache Apache 2.4.9 Apache Apache 2.4.7 Apache Apache 2.4.6 Apache Apache 2.4.35 Apache Apache 2.4.34 Apache Apache 2.4.30 Apache Apache 2.4.3 Apache Apache 2.4.29 Apache Apache 2.4.28 Apache Apache 2.4.27 Apache Apache 2.4.2 Apache Apache 2.4.1 Apache Apache 2.4.0 |
| Not Vulnerable: |
Apache Apache 2.4.39 |
Discussion
Apache HTTP Server CVE-2019-0220 Remote Security Vulnerability
Apache HTTP Server is prone to a remote security vulnerability.
An attacker can leverage this issue to perform unauthorized actions. This may aid in further attacks.
Apache HTTP Server 2.4.0 through 2.4.38 are vulnerable.
Apache HTTP Server is prone to a remote security vulnerability.
An attacker can leverage this issue to perform unauthorized actions. This may aid in further attacks.
Apache HTTP Server 2.4.0 through 2.4.38 are vulnerable.
Exploit / POC
Apache HTTP Server CVE-2019-0220 Remote Security Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apache HTTP Server CVE-2019-0220 Remote Security Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apache HTTP Server CVE-2019-0220 Remote Security Vulnerability
References:
References:
- Apache Homepage (Apache)
- Apache httpd 2.4 vulnerabilities (Apache)
- CVE-2019-0220 httpd: URL normalization inconsistency (Redhat)
- DSA-4422-1 apache2 -- security update (Debian)
- USN-3937-1: Apache HTTP Server vulnerabilities (Ubuntu)