CVE-2019-0211

Scores

EPSS

0.909high90.9%
0%20%40%60%80%100%

Percentile: 90.9%

CVSS

8.8high3.x
0246810

CVSS Score: 8.8/10

All CVSS Scores

CVSS 3.x
8.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CVSS 2.0
7.2

Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Description

In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

astradebiannvdredhatubuntu

CWEs

CWE-250CWE-416

Related Vulnerabilities

Exploits

Exploit ID: CVE-2019-0211

Source: cisa

URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

Exploit ID: 46676

Source: exploitdb

URL: https://www.exploit-db.com/exploits/46676

Recommendations

Source: nvd

All Apache users should upgrade to the latest version:
# emerge –sync
# emerge –ask –oneshot –verbose “>=www-servers/apache-2.4.39”

URL: https://security.gentoo.org/glsa/201904-20

Source: nvd

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258
After installing the updated packages, the httpd daemon will be restarted automatically.

URL: https://access.redhat.com/errata/RHSA-2019:0980

Vulnerable Software (48)

Type: Configuration

Product: apache2

Operating System: debian

Trait:
{  "fixed": "2.4.38-3"}

Source: debian

Type: Configuration

Product: apache2

Operating System: debian jessie 8

Trait:
{  "unaffected": true}

Source: debian

Type: Configuration

Product: apache2

Operating System: astra 1.6.3

Trait:
{  "unaffected": true}

Source: astra

Type: Configuration

Product: apache2

Operating System: ubuntu bionic 18.04

Trait:
{  "fixed": "2.4.29-1ubuntu4.6"}

Source: ubuntu

Type: Configuration

Product: apache2

Operating System: ubuntu cosmic 18.10

Trait:
{  "fixed": "2.4.34-1ubuntu2.1"}

Source: ubuntu

Type: Configuration

Product: apache2

Operating System: ubuntu trusty 14.04

Trait:
{  "unaffected": true}

Source: ubuntu

Type: Configuration

Product: apache2

Operating System: ubuntu xenial 16.04

Trait:
{  "fixed": "2.4.18-2ubuntu3.10"}

Source: ubuntu

Type: Configuration

Product: httpd

Operating System: rhel

Trait:
{  "fixed": "2.4-8000020190405071959.55190bc5"}

Source: redhat

Type: Configuration

Product: httpd24-httpd

Operating System: rhel

Trait:
{  "fixed": "2.4.34-7.el6.1"}

Source: redhat

Type: Configuration

Product: httpd24-httpd

Operating System: rhel

Trait:
{  "fixed": "2.4.34-7.el7.1"}

Source: redhat

Type: Configuration

Product: httpd24-httpd

Operating System: rhel

Trait:
{  "fixed": "2.4.34-7.el7.1"}

Source: redhat

Type: Configuration

Product: httpd24-httpd

Operating System: rhel

Trait:
{  "fixed": "2.4.34-7.el7.1"}

Source: redhat

Type: Configuration

Product: httpd24-httpd

Operating System: rhel

Trait:
{  "fixed": "2.4.34-7.el7.1"}

Source: redhat

Type: Configuration

Product: httpd24-mod_auth_mellon

Operating System: rhel

Trait:
{  "fixed": "0.13.1-2.el7.1"}

Source: redhat

Type: Configuration

Product: httpd24-mod_auth_mellon

Operating System: rhel

Trait:
{  "fixed": "0.13.1-2.el7.1"}

Source: redhat

Type: Configuration

Product: httpd24-mod_auth_mellon

Operating System: rhel

Trait:
{  "fixed": "0.13.1-2.el7.1"}

Source: redhat

Type: Configuration

Product: httpd24-mod_auth_mellon

Operating System: rhel

Trait:
{  "fixed": "0.13.1-2.el7.1"}

Source: redhat

Type: Configuration

Product: jbcs-httpd24-httpd

Operating System: rhel

Trait:
{  "fixed": "2.4.29-40.jbcs.el6"}

Source: redhat

Type: Configuration

Product: jbcs-httpd24-httpd

Operating System: rhel

Trait:
{  "fixed": "2.4.29-40.jbcs.el7"}

Source: redhat

Type: Configuration

Product: jbcs-httpd24-openssl

Operating System: rhel

Trait:
{  "fixed": "1.0.2n-15.jbcs.el7"}

Source: redhat