Loading HuntDB...

CVE-2019-10097

UNKNOWN
Published 2019-09-26T14:21:24
Actions:

Expert Analysis

Professional remediation guidance

Get tailored security recommendations from our analyst team for CVE-2019-10097. We'll provide specific mitigation strategies based on your environment and risk profile.

No CVSS data available

Description

In Apache HTTP Server 2.4.32-2.4.39, when mod_remoteip was configured to use a trusted intermediary proxy server using the "PROXY" protocol, a specially crafted PROXY header could trigger a stack buffer overflow or NULL pointer deference. This vulnerability could only be triggered by a trusted proxy and not by untrusted HTTP clients.

Available Exploits

No exploits available for this CVE.

Related News

No news articles found for this CVE.

GitHub Security Advisories

Community-driven vulnerability intelligence from GitHub

⚠ Unreviewed MODERATE

GHSA-x7xg-9vq9-q8xh

Advisory Details

In Apache HTTP Server 2.4.32-2.4.39, when mod_remoteip was configured to use a trusted intermediary proxy server using the "PROXY" protocol, a specially crafted PROXY header could trigger a stack buffer overflow or NULL pointer deference. This vulnerability could only be triggered by a trusted proxy and not by untrusted HTTP clients.

CVSS Scoring

CVSS Score

5.0

References

Advisory provided by GitHub Security Advisory Database. Published: May 24, 2022, Modified: May 24, 2022

References

HackerOne Reports

ccppuu
Internet Bug Bounty
Classic Buffer Overflow
Published: 2019-09-26T14:21:24
Last Modified: 2024-08-04T22:10:09.873Z
Copied to clipboard!