AZL-6475
Dashboard / Vulnerabilities / AZL-6475
Summary: CVE-2020-35452 affecting package httpd for versions less than 2.4.46-10
Details: Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP Server team could create one, though some particular compiler and/or compilation option might make it possible, with limited consequences anyway due to the size (a single byte) and the value (zero byte) of the overflow
References: https://nvd.nist.gov/vuln/detail/CVE-2020-35452
Affected packages
Package
Name: httpd
Purl: pkg:rpm/azure-linux/httpd
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -2.4.46-10
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
