QID 150401
Date Published: 2021-12-02
QID 150401: Apache HTTP Server Out of bounds read - DoS (CVE-2021-36160)
The Apache HTTP Server, colloquially called Apache, is a free and open-source cross-platform web server software.
On affected versions of Apache HTTP Server a out of bounds read vulnerability exists in "mod_proxy_uwsgi" which reads above its allocated memory and allows a remote attacker to perform a denial of service (DoS) attack.
Affected Versions:
Apache HTTP Server versions from 2.4.30 to 2.4.48.
QID Detection Logic:(Unauthenticated)
This QID sends a HTTP GET request and checks the response headers to confirm if the host is running vulnerable version of Apache HTTP Server.
Successful exploitation of this vulnerability would allow a remote attacker to perform a denial of service (DoS) attack by sending specially crafted requests and crash the target server.
- Apache HTTP Server Security Advisory -
httpd.apache.org/security/vulnerabilities_24.html
CVEs related to QID 150401
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Apache HTTP Server |
|