Description
While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The vulnerability was recently introduced in version 2.4.49. No exploit is known to the project.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Workaround
Disable the HTTP/2 protocol.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-28543 | While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The vulnerability was recently introduced in version 2.4.49. No exploit is known to the project. |
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T03:15:28.450Z
Reserved: 2021-09-20T00:00:00.000Z
Link: CVE-2021-41524
No data.
Status : Modified
Published: 2021-10-05T09:15:07.427
Modified: 2024-11-21T06:26:20.867
Link: CVE-2021-41524
OpenCVE Enrichment
No data.
Weaknesses
EUVD