Apache HTTP Server
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*
- >= 2.4.0, <= 2.4.67
A heap-based buffer overflow vulnerability has been identified in Apache HTTP Server versions 2.4.0 prior to 2.4.67. This vulnerability arises when the server is configured with malicious backend servers and uses the ProxyPassReverseCookie directive. The flaw allows an attacker to exploit the buffer overflow, potentially leading to arbitrary code execution or causing the server to crash.
Exploitation of this vulnerability causes a heap-based buffer overflow, which can lead to memory corruption. Such heap-overflow vulnerabilities are often exploitable, allowing for arbitrary code execution or causing the server to crash.
Users are advised to upgrade to Apache HTTP Server version 2.4.68, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.