Description
Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using both Content-Length and Transfer-Encoding headers, leading to a Denial of Service
Remediation
References
Related Vulnerabilities
Internet Information Services Other Vulnerability (CVE-1999-0191)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-2039)
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-5651)
Lighttpd Resource Management Errors Vulnerability (CVE-2010-0295)