Bug 1191326 - (CVE-2021-41524) VUL-0: CVE-2021-41524: apache2: null pointer dereference in h2 fuzzing
(CVE-2021-41524)
VUL-0: CVE-2021-41524: apache2: null pointer dereference in h2 fuzzing
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P5 - None : Normal
: ---
Assigned To: Petr Gajdos
Security Team bot
https://smash.suse.de/issue/311740
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2021-10-05 11:50 UTC by Robert Frohl
Modified: 2021-10-05 12:21 UTC (History)
0 users

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Frohl 2021-10-05 11:50:34 UTC
moderate: null pointer dereference in h2 fuzzing (CVE-2021-41524)

    While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing,

    allowing an external source to DoS the server. This requires a specially crafted request.

    The vulnerability was recently introduced in version 2.4.49. No exploit is known to the project.

    Acknowledgements: Apache httpd team would like to thank LI ZHI XIN from NSFocus Security Team for reporting this issue.
    Reported to security team	2021-09-17
    fixed by r1893655 in 2.4.x	2021-09-26
    Update 2.4.50 released	2021-10-04
    Affects	2.4.49

https://httpd.apache.org/security/vulnerabilities_24.html
Comment 1 Petr Gajdos 2021-10-05 11:57:59 UTC
2.4.50 is on its way to Factory.