imPC@ndo IT

Tracker / CVE-2019-10097

CVE-2019-10097

High 7.2

In Apache HTTP Server 2.4.32-2.4.39, when mod_remoteip was configured to use a trusted intermediary proxy server using the "PROXY" protocol, a specially crafted PROXY header could trigger a stack buffer overflow or NULL pointer deference. This vulnerability could only be triggered by a trusted proxy and not by untrusted HTTP clients.

Affected products and versions

apache http_server
oracle communications_element_manager
oracle communications_session_report_manager
oracle communications_session_route_manager
oracle enterprise_manager_ops_center
oracle http_server
oracle instantis_enterprisetrack · 17.1 → 17.3
oracle retail_xstore_point_of_service

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References