Apache – CVE-2020-13950

Description

Cytrix has detected that the Version of Apache HTTP Server being used is vulnerable to a ‘mod_proxy_http’ null pointer dereference.

CVE-2020-13950 is categorized as a ‘NULL Pointer Dereference’ vulnerability (CWE-476).
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is actually NULL.
That, will probably cause a crash or an exit.

NULL pointer dereference issues can occur through a number of flaws, including race conditions, and simple programming omissions.

Attackers could cause the ‘mod_proxy_http’ to crash (via NULL pointer dereference).
They do that by crafting requests that uses both Content-Length and Transfer-Encoding headers, which could lead to a Denial of Service (DoS).

It could lead to a decrease in performance and interruptions in the availability of resources.

Recommendation

To fix CVE-2020-13950, upgrade the version of Apache HTTP Server being used to 2.4.48.

References

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13950

https://cwe.mitre.org/data/definitions/476.html

< Return to all Vulnerabilities

What is a CWE ?

Similar to the article written on CVEs, in this article we will answer the questions :What is CWE ? and, what is the difference between

Read More »

Servers 101

Let’s have a “quick” Servers 101 Course. Courtesy of Cytrix! If you’ve been on the internet for over an hour, you probably already heard of

Read More »