QID 352857

Date Published: 2021-10-22

QID 352857: Amazon Linux Security Advisory for httpd24: ALAS-2021-1543

A null pointer dereference was found in apache httpd mod_h2.
The highest threat from this flaw is to system integrity. (
( CVE-2021-33193) a null pointer dereference in httpd allows an unauthenticated remote attacker to crash httpd by providing malformed http requests.
The highest threat from this vulnerability is to system availability. (
( CVE-2021-34798) an out-of-bounds read in mod_proxy_uwsgi of httpd allows a remote unauthenticated attacker to crash the service through a crafted request.
( CVE-2021-36160) an out-of-bounds write in function ap_escape_quotes of httpd allows an unauthenticated remote attacker to crash the server or potentially execute code on the system with the privileges of the httpd user, by providing malicious input to the function. (
( CVE-2021-39275)



Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

Allows unauthorized disclosure of information; allows unauthorized modification; allows disruption of service.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Please refer to Amazon advisory: ALAS-2021-1543 for affected packages and patching details, or update with your package manager.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ALAS-2021-1543 Amazon Linux URL Logo alas.aws.amazon.com/ALAS-2021-1543.html