REDHAT-BUG-2465296: Null Pointer Dereference
A NULL pointer dereference in moddavlock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.moddavlock is not used internally by moddav or moddavfs.
The only known use-case for moddavlock was moddavsvn from Apache Subversion earlier than version 1.2.0.
Users are recommended to upgrade to version 2.4.66, which fixes this issue, or remove moddavlock.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
apache/httpd (mod_dav_lock)to a version that resolves this vulnerability.Fixed in 2.4.66 - Remove
Remove
apache/httpd/mod_dav_lockfrom your environment.Remove/uninstall the mod_dav_lock module if it is not required.
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2465296?
The severity of REDHAT-BUG-2465296 is classified as low.
How do I fix REDHAT-BUG-2465296?
To fix REDHAT-BUG-2465296, upgrade to Apache HTTP Server 2.4.67 or later.
What causes the vulnerability REDHAT-BUG-2465296?
REDHAT-BUG-2465296 is caused by a NULL pointer dereference in the mod_dav_lock module of Apache HTTP Server.
What versions of Apache HTTP Server are affected by REDHAT-BUG-2465296?
Apache HTTP Server versions 2.4.66 and earlier are affected by REDHAT-BUG-2465296.
What potential impact does REDHAT-BUG-2465296 have?
The potential impact of REDHAT-BUG-2465296 is that an attacker may crash the server with a malicious request.