In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2706-1 | apache2 security update |
Debian DSA |
DSA-4937-1 | apache2 security update |
Ubuntu USN |
USN-4994-1 | Apache HTTP Server vulnerabilities |
Ubuntu USN |
USN-4994-2 | Apache HTTP Server vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-03T20:33:40.152Z
Reserved: 2021-02-04T00:00:00
Link: CVE-2021-26691
No data.
Status : Modified
Published: 2021-06-10T07:15:07.580
Modified: 2024-11-21T05:56:41.067
Link: CVE-2021-26691
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
Ubuntu USN