Apache HTTP Server
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*
- 2.4.66
A double free vulnerability with the potential for remote code execution has been identified in Apache HTTP Server 2.4.66, specifically within the HTTP/2 protocol handling. This vulnerability arises from improper memory management, which could be exploited under certain conditions.
Exploitation of this vulnerability can lead to a double free condition, which may be exploited to execute arbitrary code remotely, depending on the server's configuration and the nature of the injected payload.
Users are advised to upgrade to Apache HTTP Server version 2.4.67, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.