CVE-2006-20001

HIGH7.5EPSS 0.47%

apache2 - security update

發布日:2023/1/17修改日:2025/11/19
也稱為:DSA-5376-1ALPINE-CVE-2006-20001DEBIAN-CVE-2006-20001DEBIAN-CVE-2022-36760DEBIAN-CVE-2022-37436DEBIAN-CVE-2023-25690DEBIAN-CVE-2023-27522

描述

A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash. This issue affects Apache HTTP Server 2.4.54 and earlier.

受影響套件(4)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

參考連結(2)