CVE-2019-10097: Use After Free
A vulnerability was discovered in Apache httpd, in modremoteip. A trusted proxy using the "PROXY" protocol could send specially crafted headers that can cause httpd to experience a stack buffer overflow or NULL pointer dereference, leading to a crash or other potential consequences. This issue could only be exploited by configured trusted intermediate proxy servers. HTTP clients such as browsers could not exploit the vulnerability.
Other sources
A vulnerability was found in httpd, where modremoteip was configured to use a trusted intermediary proxy server using the "PROXY" protocol, a specially crafted PROXY header could trigger a stack buffer overflow or NULL pointer deference. This vulnerability could only be triggered by a trusted proxy and not by untrusted HTTP clients.
— Red Hat
In Apache HTTP Server 2.4.32-2.4.39, when modremoteip was configured to use a trusted intermediary proxy server using the "PROXY" protocol, a specially crafted PROXY header could trigger a stack buffer overflow or NULL pointer deference. This vulnerability could only be triggered by a trusted proxy and not by untrusted HTTP clients.
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2019-10097?
CVE-2019-10097 is a vulnerability discovered in Apache HTTP Server 2.4.32-2.4.39 when mod_remoteip is configured to use a trusted intermediary.
What is the severity of CVE-2019-10097?
The severity of CVE-2019-10097 is medium with a CVSS score of 6.6.
How does CVE-2019-10097 affect Apache httpd?
CVE-2019-10097 can cause Apache httpd to experience a stack buffer overflow or NULL pointer dereference, leading to a crash or other potential consequences.
Which versions of Apache httpd are affected by CVE-2019-10097?
Versions 2.4.32 to 2.4.39 of Apache httpd are affected by CVE-2019-10097.
How can I fix CVE-2019-10097?
To fix CVE-2019-10097, upgrade to version 2.4.41 of Apache httpd.