CVE-2020-11984: Buffer Overflow
A flaw was found in Apache httpd in versions 2.4.32 to 2.4.46. The uwsgi protocol does not serialize more than 16K of HTTP header leading to resource exhaustion and denial of service. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Other sources
A flaw was found in httpd before version 2.4.46. The uwsgi protocol does not let us serialize more than 16K of HTTP header leading to resource exhaustion and denial of service.
Upstream patch:
http://svn.apache.org/viewvc?view=revision&revision=1880251
— Red Hat
Apache HTTP server 2.4.32 to 2.4.44 modproxyuwsgi info disclosure and possible RCE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jbcs-httpd24-aprto a version that resolves this vulnerability.Fixed in 0:1.6.3-104.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-apr-utilto a version that resolves this vulnerability.Fixed in 0:1.6.1-75.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-brotlito a version that resolves this vulnerability.Fixed in 0:1.0.6-38.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-curlto a version that resolves this vulnerability.Fixed in 0:7.64.1-44.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.37-64.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-janssonto a version that resolves this vulnerability.Fixed in 0:2.11-53.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-nghttp2to a version that resolves this vulnerability.Fixed in 0:1.39.2-34.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-opensslto a version that resolves this vulnerability.Fixed in 1:1.1.1c-32.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-aprto a version that resolves this vulnerability.Fixed in 0:1.6.3-104.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-apr-utilto a version that resolves this vulnerability.Fixed in 0:1.6.1-75.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-brotlito a version that resolves this vulnerability.Fixed in 0:1.0.6-38.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-curlto a version that resolves this vulnerability.Fixed in 0:7.64.1-44.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.37-64.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-janssonto a version that resolves this vulnerability.Fixed in 0:2.11-53.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-nghttp2to a version that resolves this vulnerability.Fixed in 0:1.39.2-34.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-opensslto a version that resolves this vulnerability.Fixed in 1:1.1.1c-32.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-openssl-chilto a version that resolves this vulnerability.Fixed in 0:1.0.0-1.jbcs.el7 - Upgrade
Upgrade
redhat/httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.34-22.el7 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.44 - Upgrade
Upgrade
debian/apache2to a version that resolves this vulnerability.Fixed in 2.4.62-1~deb11u1Fixed in 2.4.67-1~deb11u3Fixed in 2.4.68-1~deb12u1Fixed in 2.4.67-1~deb12u3Fixed in 2.4.68-1~deb13u1Fixed in 2.4.67-1~deb13u3Fixed in 2.4.68-1 - Configuration
To disable the vulnerable module, comment out the line "LoadModule proxy_uwsgi_module modules/mod_proxy_uwsgi.so" in /etc/httpd/conf.modules.d/00-proxy.conf. This will disable loading of mod_proxy_uwsgi (the flaw only affects configurations that use the uwsgi protocol).
Apache httpd (mod_proxy_uwsgi) LoadModule proxy_uwsgi_module modules/mod_proxy_uwsgi.so (in /etc/httpd/conf.modules.d/00-proxy.conf) = comment out
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-11984?
CVE-2020-11984 is a vulnerability found in Apache HTTP server versions 2.4.32 to 2.4.44.
What is the severity of CVE-2020-11984?
The severity of CVE-2020-11984 is critical.
How does CVE-2020-11984 impact data confidentiality and integrity?
CVE-2020-11984 can lead to data confidentiality and integrity issues.
How do I fix CVE-2020-11984?
To fix CVE-2020-11984, upgrade Apache HTTP server to version 2.4.44 or higher.
Where can I find more information about CVE-2020-11984?
You can find more information about CVE-2020-11984 in the references provided: http://svn.apache.org/viewvc?view=revision&revision=1880251, https://access.redhat.com/support/policy/updates/jboss_notes, https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1868148.