Description
The read_request_line function in server/protocol.c in the Apache HTTP Server 2.4.12 does not initialize the protocol structure member, which allows remote attackers to cause a denial of service (NULL pointer dereference and process crash) by sending a request that lacks a method to an installation that enables the INCLUDES filter and has an ErrorDocument 400 directive specifying a local URI.
Remediation
References
Related Vulnerabilities
WordPress Plugin Gallery Plugin for WordPress-Envira Photo Gallery Cross-Site Scripting (1.7.6)
WordPress Plugin MATRIX 3D Cross-Site Scripting (1.2)
WordPress Plugin AccessPress Anonymous Post Pro Arbitrary File Upload (3.1.9)
WordPress Plugin MiniCart SQL Injection (1.00.1)
WebLogic Deserialization of Untrusted Data Vulnerability (CVE-2019-14540)