We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-36387

Apache HTTP Server: DoS by Null pointer in websocket over HTTP/2



Assignerapache
Reserved2024-05-27
Published2024-07-01
Updated2024-09-13

Description

Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.

Problem types

CWE-476 NULL Pointer Dereference

Product status

Default status
unaffected

2.4.55
affected

Timeline

2024-05-27:fixed in r1918003 in trunk

Credits

Marc Stern (<marc.stern@approach-cyber.com>) 0x4008988190

References

https://httpd.apache.org/security/vulnerabilities_24.html vendor-advisory

https://security.netapp.com/advisory/ntap-20240712-0001/

cve.org CVE-2024-36387

nvd.nist.gov CVE-2024-36387

Download JSON

Share this page
https://cve.threatint.com
Subscribe to our newsletter to learn more about our work.