CVE-2019-0211
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.
Affected (68)
Show all products
Apache: Http Server · Fedoraproject: Fedora · Canonical: Ubuntu Linux · Debian: Debian Linux · Opensuse: Leap · Netapp: Oncommand Unified Manager · Redhat: Enterprise Linux, Enterprise Linux Eus, Enterprise Linux For Arm 64, Enterprise Linux For Arm 64 Eus, Enterprise Linux For Ibm Z Systems, Enterprise Linux For Ibm Z Systems Eus, Enterprise Linux For Power Little Endian, Enterprise Linux For Power Little Endian Eus, Enterprise Linux Server Aus, Enterprise Linux Server Tus, Enterprise Linux Update Services For Sap Solutions, Jboss Core Services, Openshift Container Platform, Openshift Container Platform For Power, Software Collections · Oracle: Communications Session Report Manager, Communications Session Route Manager, Enterprise Manager Ops Center, Http Server, Instantis Enterprisetrack, Retail Xstore Point Of Service
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.4.17 to 2.4.38 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 28 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 14.04 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.0 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.0 | |
| Version 8.1 | |
| Version 8.0_aarch64 | |
| Version 8.1_aarch64 | |
| Version 8.0_s390x | |
| Version 8.1_s390x | |
| Version 8.0_ppc64le | |
| Version 8.1_ppc64le | |
| Version 8.2 | |
| Version 8.2 | |
| Version 8.0 | |
| Version 1.0 | |
| Version 3.11 | |
| Version 3.11_ppc64le | |
| Version 1.0 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.0.0 | |
| Version 8.0.0 | |
| Version 12.3.3 | |
| Version 12.2.1.3.0 | |
| Version 17.1 | |
| Version 7.0 |
References (103)
Source: security@apache.org
Broken LinkMailing ListRelease NotesThird Party Advisory
Source: security@apache.org
Broken LinkMailing ListRelease NotesThird Party Advisory
Source: security@apache.org
Broken LinkThird Party Advisory
Source: security@apache.org
Third Party AdvisoryVDB Entry
Source: security@apache.org
ExploitThird Party AdvisoryVDB Entry
Source: security@apache.org
ExploitThird Party AdvisoryVDB Entry
Source: security@apache.org
Broken LinkVendor Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Broken LinkThird Party AdvisoryVDB Entry
Source: security@apache.org
Mailing List
Source: security@apache.org
Mailing List
Source: security@apache.org
Mailing List
Source: security@apache.org
Mailing List
Source: security@apache.org
Mailing List
Source: security@apache.org
Mailing List
Source: security@apache.org
Mailing List
Source: security@apache.org
Mailing List
Source: security@apache.org
Mailing List
Source: security@apache.org
Mailing List
Source: security@apache.org
Mailing List
Source: security@apache.org
Mailing ListPatch
Source: security@apache.org
Mailing List
Source: security@apache.org
Mailing List
Source: security@apache.org
Mailing List
Source: security@apache.org
Mailing List
Source: security@apache.org
Mailing List
Source: security@apache.org
Mailing List
Source: security@apache.org
Release Notes
Source: security@apache.org
Release Notes
Source: security@apache.org
Release Notes
Source: security@apache.org
Mailing ListPatchThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
ExploitThird Party AdvisoryVDB Entry
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkMailing ListRelease NotesThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkMailing ListRelease NotesThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource
Timeline
No history available yet.