This issue affects Apache HTTP Server 2.4.54 and earlier.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3351-1 | apache2 security update |
Debian DSA |
DSA-5376-1 | apache2 security update |
EUVD |
EUVD-2006-2000 | A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash. This issue affects Apache HTTP Server 2.4.54 and earlier. |
Ubuntu USN |
USN-5834-1 | Apache HTTP Server vulnerabilities |
Ubuntu USN |
USN-5839-1 | Apache HTTP Server vulnerabilities |
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 13 Feb 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Feb 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash. This issue affects Apache HTTP Server 2.4.54 and earlier. | A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash. This issue affects Apache HTTP Server 2.4.54 and earlier. |
Wed, 07 Aug 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-02-13T16:27:07.996Z
Reserved: 2022-09-01T14:24:05.065Z
Link: CVE-2006-20001
Updated: 2024-08-07T20:57:41.059Z
Status : Modified
Published: 2023-01-17T20:15:11.177
Modified: 2025-02-13T17:15:21.913
Link: CVE-2006-20001
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN