Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier.

Project Subscriptions

Vendors Products
Http Server Subscribe
Broadcom Subscribe
Brocade Fabric Operating System Firmware Subscribe
Debian Linux Subscribe
Fedoraproject Subscribe
Cloud Backup Subscribe
Clustered Data Ontap Subscribe
Storagegrid Subscribe
Communications Cloud Native Core Network Function Cloud Native Environment Subscribe
Enterprise Manager Base Platform Subscribe
Http Server Subscribe
Instantis Enterprisetrack Subscribe
Peoplesoft Enterprise Peopletools Subscribe
Zfs Storage Appliance Kit Subscribe
Enterprise Linux Subscribe
Jboss Core Services Subscribe
Rhel Software Collections Subscribe
Siemens Subscribe
Ruggedcom Nms Subscribe
Sinec Nms Subscribe
Sinema Remote Connect Server Subscribe
Sinema Server Subscribe
Tenable Subscribe
Tenable.sc Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-2776-1 apache2 security update
Debian DSA Debian DSA DSA-4982-1 apache2 security update
Ubuntu USN Ubuntu USN USN-5090-1 Apache HTTP Server vulnerabilities
Ubuntu USN Ubuntu USN USN-5090-2 Apache HTTP Server vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://httpd.apache.org/security/vulnerabilities_24.html cve-icon cve-icon
https://cert-portal.siemens.com/productcert/pdf/ssa-685781.pdf cve-icon cve-icon
https://httpd.apache.org/security/vulnerabilities_24.html cve-icon
https://kc.mcafee.com/corporate/index?page=content&id=SB10379 cve-icon cve-icon
https://lists.apache.org/thread.html/r3925e167d5eb1c75def3750c155d753064e1d34a143028bb32910432%40%3Cusers.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r61fdbfc26ab170f4e6492ef3bd5197c20b862ce156e9d5a54d4b899c%40%3Cusers.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r82838efc5fa6fc4c73986399c9b71573589f78b31846aff5bd9b1697%40%3Cusers.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r82c077663f9759c7df5a6656f925b3ee4f55fcd33c889ba7cd687029%40%3Cusers.httpd.apache.org%3E cve-icon cve-icon
https://lists.debian.org/debian-lts-announce/2021/10/msg00001.html cve-icon cve-icon
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7TJOHX7RHWD/ cve-icon cve-icon
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3HDQK4VP45R/ cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2021-34798 cve-icon
https://security.gentoo.org/glsa/202208-20 cve-icon cve-icon
https://security.netapp.com/advisory/ntap-20211008-0004/ cve-icon cve-icon
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-2.4.49-VWL69sWQ cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2021-34798 cve-icon
https://www.debian.org/security/2021/dsa-4982 cve-icon cve-icon
https://www.oracle.com/security-alerts/cpuapr2022.html cve-icon cve-icon
https://www.oracle.com/security-alerts/cpujan2022.html cve-icon cve-icon
https://www.tenable.com/security/tns-2021-17 cve-icon cve-icon
History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-08-04T00:26:54.014Z

Reserved: 2021-06-16T00:00:00

Link: CVE-2021-34798

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-09-16T15:15:07.267

Modified: 2024-11-21T06:11:13.650

Link: CVE-2021-34798

cve-icon Redhat

Severity : Moderate

Publid Date: 2021-09-16T00:00:00Z

Links: CVE-2021-34798 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses