First published: Tue Jan 17 2023(Updated: )
A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash. This issue affects Apache HTTP Server 2.4.54 and earlier.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache HTTP server | <2.4.55 | |
redhat/httpd | <2.4.55 | 2.4.55 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2006-20001.
The severity of CVE-2006-20001 is high.
CVE-2006-20001 affects Apache HTTP Server 2.4.54 and earlier.
To fix CVE-2006-20001, update Apache HTTP Server to version 2.4.55 or later.
The CWE ID for CVE-2006-20001 is CWE-787.