Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP Server team could create one, though some particular compiler and/or compilation option might make it possible, with limited consequences anyway due to the size (a single byte) and the value (zero byte) of the overflow
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2706-1 | apache2 security update |
Debian DSA |
DSA-4937-1 | apache2 security update |
Ubuntu USN |
USN-4994-1 | Apache HTTP Server vulnerabilities |
Ubuntu USN |
USN-4994-2 | Apache HTTP Server vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T17:02:08.055Z
Reserved: 2020-12-14T00:00:00.000Z
Link: CVE-2020-35452
No data.
Status : Modified
Published: 2021-06-10T07:15:07.493
Modified: 2024-11-21T05:27:18.390
Link: CVE-2020-35452
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
Ubuntu USN