QID 730312

Date Published: 2021-12-23

QID 730312: Apache Hypertext Transfer Protocol (HTTP) Server Buffer Overflow Vulnerability

Apache HTTP Server is a free and open-source cross-platform web server software, released under the terms of Apache License 2.0.

A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts).

Affected Versions:
Apache HTTP Server 2.4.51 and earlier

QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable Apache Version by grabbing the banner from HTTP response

Successful exploitation of the vulnerability may allow remote code execution and complete system compromise.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to update to Apache HTTP Server 2.4.52 or later. For more information, check Apache Security Advisory

    Vendor References

    CVEs related to QID 730312

    Software Advisories
    Advisory ID Software Component Link
    Apache Security Advisory URL Logo httpd.apache.org/security/vulnerabilities_24.html