REDHAT-BUG-2466913: Buffer Overflow
Heap-based Buffer Overflow vulnerability in modproxyajp of Apache HTTP Server. If modproxyajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to modproxyajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer.
This issue affects Apache HTTP Server: through 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache HTTP Server (mod_proxy_ajp)to a version that resolves this vulnerability.Fixed in 2.4.67
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2466913?
The severity of REDHAT-BUG-2466913 is classified as high, with a score of 7.
What type of vulnerability is REDHAT-BUG-2466913?
REDHAT-BUG-2466913 is a heap-based buffer overflow vulnerability in mod_proxy_ajp of Apache HTTP Server.
How does REDHAT-BUG-2466913 affect Apache HTTP Server?
REDHAT-BUG-2466913 allows a malicious AJP server to send crafted messages that can overwrite memory, potentially leading to code execution.
How can I fix REDHAT-BUG-2466913?
To fix REDHAT-BUG-2466913, ensure that you update Apache HTTP Server to the latest version that addresses this vulnerability.
What software is impacted by REDHAT-BUG-2466913?
REDHAT-BUG-2466913 affects the Apache HTTP Server specifically related to its mod_proxy_ajp module.