CVE-2019-0190: High severity Apache HTTP Server vulnerability
A bug exists in the way modssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause modssl to enter a loop leading to a denial of service. This bug can be only triggered with Apache HTTP Server version 2.4.37 when using OpenSSL version 1.1.1 or later, due to an interaction in changes to handling of renegotiation attempts.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-0190?
CVE-2019-0190 is a vulnerability in Apache HTTP Server version 2.4.37 when using OpenSSL version 1.1.1 or later.
What is the severity of CVE-2019-0190?
The severity of CVE-2019-0190 is high, with a CVSS score of 7.5.
How does CVE-2019-0190 work?
CVE-2019-0190 allows a remote attacker to send a carefully crafted request, causing mod_ssl to enter a loop and leading to a denial of service.
Which software versions are affected by CVE-2019-0190?
CVE-2019-0190 affects Apache HTTP Server version 2.4.37 when using OpenSSL version 1.1.1 or later.
How can I mitigate CVE-2019-0190?
To mitigate CVE-2019-0190, upgrade to a version of Apache HTTP Server that is not affected or apply the necessary patches provided by the vendor.