Tracker / CVE-2020-9490
CVE-2020-9490
Alta 7.5
Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via "H2Push off" will mitigate this vulnerability for unpatched servers.
Prodotti e versioni affette
| apache | http_server · 2.4.20 → 2.4.46 |
|---|---|
| canonical | ubuntu_linux |
| debian | debian_linux |
| fedoraproject | fedora |
| opensuse | leap |
| oracle | communications_element_manager · 8.2.0 → 8.2.2 |
| oracle | communications_session_report_manager · 8.2.0 → 8.2.2 |
| oracle | communications_session_route_manager · 8.2.0 → 8.2.2 |
| oracle | enterprise_manager_ops_center |
| oracle | hyperion_infrastructure_technology |
| oracle | instantis_enterprisetrack |
| oracle | zfs_storage_appliance_kit |
| redhat | enterprise_linux |
| redhat | enterprise_linux_eus |
| redhat | enterprise_linux_for_ibm_z_systems |
| redhat | enterprise_linux_for_ibm_z_systems_eus |
| redhat | enterprise_linux_for_power_little_endian |
| redhat | enterprise_linux_for_power_little_endian_eus |
| redhat | enterprise_linux_server_aus |
| redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions |
| redhat | enterprise_linux_server_tus |
| redhat | enterprise_linux_server_update_services_for_sap_solutions |
| redhat | openstack |
| redhat | openstack_for_ibm_power |
| redhat | software_collections |
Analisi
Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.