Impact
A NULL pointer dereference has been discovered in the mod_heartmonitor module of Apache HTTP Server. The flaw is triggered when the unicast listener processes malformed or crafted traffic, causing the server process to crash and become unavailable. The impact is a denial of service that can affect the entire HTTP service without providing any other system compromise.
Affected Systems
Apache HTTP Server versions from 2.4.0 to 2.4.68, inclusive, are impacted. The vulnerability exists in the core mod_heartmonitor module used by these releases.
Risk and Exploitability
The CVSS score is not supplied, but the vulnerability permits a simple network-based attack that can be executed by sending a crafted packet to the unicast listener. The EPSS score is unavailable, and the flaw has not been listed in the CISA KEV catalog, indicating no known widespread exploitation yet. Nevertheless, the potential for service disruption warrants immediate attention.
OpenCVE Enrichment