CVE-2020-1934: Medium severity Apache HTTP Server vulnerability
A flaw was found in Apache's HTTP server (httpd) .The modproxyftp module may use uninitialized memory with proxying to a malicious FTP server. The highest threat from this vulnerability is to data confidentiality.
Other sources
In Apache HTTP Server 2.4.0 to 2.4.41, modproxyftp may use uninitialized memory when proxying to a malicious FTP server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jbcs-httpd24-curlto a version that resolves this vulnerability.Fixed in 0:7.64.1-36.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.37-57.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-nghttp2to a version that resolves this vulnerability.Fixed in 0:1.39.2-25.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-curlto a version that resolves this vulnerability.Fixed in 0:7.64.1-36.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.37-57.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-nghttp2to a version that resolves this vulnerability.Fixed in 0:1.39.2-25.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-openssl-pkcs11to a version that resolves this vulnerability.Fixed in 0:0.4.10-7.jbcs.el7 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 0:2.4.6-95.el7 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.42 - Upgrade
Upgrade
debian/apache2to a version that resolves this vulnerability.Fixed in 2.4.62-1~deb11u1Fixed in 2.4.67-1~deb11u3Fixed in 2.4.68-1~deb12u1Fixed in 2.4.67-1~deb12u3Fixed in 2.4.68-1~deb13u1Fixed in 2.4.67-1~deb13u3Fixed in 2.4.68-1 - Upgrade
Upgrade
apache/httpd mod_proxy_ftpto a version that resolves this vulnerability.Fixed in 2.4.42
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2020-1934?
The severity of CVE-2020-1934 is medium with a severity value of 5.3.
How does CVE-2020-1934 affect Apache HTTP Server versions?
CVE-2020-1934 affects Apache HTTP Server versions 2.4.0 to 2.4.41.
What is the highest threat from CVE-2020-1934?
The highest threat from CVE-2020-1934 is to data confidentiality.
How can I fix CVE-2020-1934 on Apache HTTP Server?
To fix CVE-2020-1934 on Apache HTTP Server, upgrade to version 2.4.42.
Where can I find more information about CVE-2020-1934?
You can find more information about CVE-2020-1934 at the following references: [Link1](https://httpd.apache.org/security/vulnerabilities_24.html), [Link2](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1820776), [Link3](https://svn.apache.org/viewvc?view=revision&revision=1873745).