CVE-2019-0211
Vulnerability Summary
Timeline
Description
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.
CVSS Metrics
- v3.1•HIGH•Score: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- v2.0•HIGH•Score: 7.2AV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS Trends
Current EPSS score: 89.57%• Percentile: 100%
Techniques & Countermeasures
- CWE-416•Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
Affected Systems
- apache•apache_http_server
2.4.17 to 2.4.38
- Unknown•HTTP Server
≥ 2.4.17, ≤ 2.4.38
- canonical•ubuntu_linux
14.04 | 16.04 | 18.04 | 18.10
- debian•debian_linux
9.0
- fedoraproject•fedora
28 | 29 | 30
- netapp•oncommand_unified_manager
na
- opensuse•leap
15.0 | 42.3
- oracle•communications_session_report_manager
8.0.0 | 8.1.0 | 8.1.1 | 8.2.0
- oracle•communications_session_route_manager
8.0.0 | 8.1.0 | 8.1.1 | 8.2.0
- oracle•enterprise_manager_ops_center
12.3.3 | 12.4.0
- oracle•http_server
12.2.1.3.0
- oracle•instantis_enterprisetrack
17.1 | 17.2 | 17.3
- oracle•retail_xstore_point_of_service
7.0 | 7.1
- redhat•enterprise_linux
8.0
- redhat•enterprise_linux_eus
8.1 | 8.2 | 8.4 | 8.6 | 8.8
- redhat•enterprise_linux_for_arm_64
8.0_aarch64
- redhat•enterprise_linux_for_arm_64_eus
8.1_aarch64 | 8.2_aarch64 | 8.4_aarch64 | 8.6_aarch64 | 8.8_aarch64
- redhat•enterprise_linux_for_ibm_z_systems
8.0_s390x
- redhat•enterprise_linux_for_ibm_z_systems_eus
8.1_s390x | 8.2_s390x | 8.4_s390x | 8.6_s390x | 8.8_s390x
- redhat•enterprise_linux_for_power_little_endian
8.0_ppc64le
- redhat•enterprise_linux_for_power_little_endian_eus
8.1_ppc64le | 8.2_ppc64le | 8.4_ppc64le | 8.6_ppc64le | 8.8_ppc64le
- redhat•enterprise_linux_server_aus
8.2 | 8.4 | 8.6
- redhat•enterprise_linux_server_tus
8.2 | 8.4 | 8.6 | 8.8
- redhat•enterprise_linux_update_services_for_sap_solutions
8.0 | 8.1 | 8.4 | 8.6 | 8.8
- redhat•jboss_core_services
1.0
- redhat•openshift_container_platform
3.11
- redhat•openshift_container_platform_for_power
3.11_ppc64le
- redhat•software_collections
1.0
References (52)
- http://www.openwall.com/lists/oss-security/2019/04/02/3
- http://www.securityfocus.com/bid/107666
- https://seclists.org/bugtraq/2019/Apr/5
- https://www.synology.com/security/advisory/Synology_SA_19_14
- http://packetstormsecurity.com/files/152386/Apache-2.4.38-Root-Privilege-Escalation.html
- https://usn.ubuntu.com/3937-1/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WETXNQWNQLWHV6XNW6YTO5UGDTIWAQGT/
- https://www.debian.org/security/2019/dsa-4422
- https://lists.apache.org/thread.html/b1613d44ec364c87bb7ee8c5939949f9b061c05c06e0e90098ebf7aa%40%3Cusers.httpd.apache.org%3E
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EZRMTEIGZKYFNGIDOTXN3GNEJTLVCYU7/
- https://seclists.org/bugtraq/2019/Apr/16
- https://www.exploit-db.com/exploits/46676/
- https://httpd.apache.org/security/vulnerabilities_24.html
- http://packetstormsecurity.com/files/152415/Slackware-Security-Advisory-httpd-Updates.html
- http://packetstormsecurity.com/files/152441/CARPE-DIEM-Apache-2.4.x-Local-Privilege-Escalation.html
- http://www.apache.org/dist/httpd/CHANGES_2.4.39
- https://lists.apache.org/thread.html/890507b85c30adf133216b299cc35cd8cd0346a885acfc671c04694e%40%3Cdev.community.apache.org%3E
- https://lists.apache.org/thread.html/b2bdb308dc015e771ba79c0586b2de6fb50caa98b109833f5d4daf28%40%3Cdev.community.apache.org%3E
- https://access.redhat.com/errata/RHSA-2019:0746
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00051.html
- https://lists.apache.org/thread.html/de881a130bc9cb2f3a9ff220784520556884fb8ea80e69400a45509e%40%3Cdev.community.apache.org%3E
- https://support.f5.com/csp/article/K32957101
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00061.html
- https://security.gentoo.org/glsa/201904-20
- https://security.netapp.com/advisory/ntap-20190423-0001/
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00084.html
- https://access.redhat.com/errata/RHSA-2019:0980
- https://access.redhat.com/errata/RHBA-2019:0959
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ALIR5S3O7NRHEGFMIDMUSYQIZOE4TJJN/
- https://access.redhat.com/errata/RHSA-2019:1297
- https://access.redhat.com/errata/RHSA-2019:1296
- https://lists.apache.org/thread.html/fd110f4ace2d8364c7d9190e1993cde92f79e4eb85576ed9285686ac%40%3Ccvs.httpd.apache.org%3E
- https://access.redhat.com/errata/RHSA-2019:1543
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
- http://www.openwall.com/lists/oss-security/2019/07/26/7
- https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03950en_us
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
- https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3E
- https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r06f0d87ebb6d59ed8379633f36f72f5b1f79cadfda72ede0830b42cf%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r03ee478b3dda3e381fd6189366fa7af97c980d2f602846eef935277d%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/rd2fb621142e7fa187cfe12d7137bf66e7234abcbbcd800074c84a538%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/re473305a65b4db888e3556e4dae10c2a04ee89dcff2e26ecdbd860a9%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3E
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-0211