CVE-2019-10081

NameCVE-2019-10081
DescriptionHTTP/2 (2.4.20 through 2.4.39) very early pushes, for example configured with "H2PushResource", could lead to an overwrite of memory in the pushing request's pool, leading to crashes. The memory copied is that of the configured push link header values, not data supplied by the client.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-4509-1
NVD severitymedium (attack range: remote)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
apache2 (PTS)jessie2.4.10-10+deb8u12fixed
jessie (security)2.4.10-10+deb8u15fixed
stretch (security), stretch2.4.25-3+deb9u8fixed
buster, buster (security)2.4.38-3+deb10u1fixed
bullseye, sid2.4.41-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
apache2source(unstable)2.4.41-1medium
apache2sourcebuster2.4.38-3+deb10u1mediumDSA-4509-1
apache2sourcejessie(not affected)
apache2sourcestretch2.4.25-3+deb9u8mediumDSA-4509-1

Notes

[jessie] - apache2 <not-affected> (HTTP/2 support only available since version 2.4.17 and later)
Affects upstream versions 2.4.20 to 2.4.39
https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2019-10081

Search for package or bug name: Reporting problems