Description
Apache mod_rewrite is prone to an off-by-one buffer-overflow condition. The vulnerability arising in the mod_rewrite module's ldap scheme handling allows for potential memory corruption when an attacker exploits certain rewrite rules.
Affected Apache versions:
- Apache 1.3.28 - 1.3.36 with mod_rewrite
- Apache 2.2.0 - 2.2.2 with mod_rewrite
- Apache 2.0.46 - 2.0.58 with mod_rewrite
Remediation
Upgrade Apache to the latest version.
References
Related Vulnerabilities
WordPress Plugin Integration for Contact Form 7 and Pipedrive Cross-Site Scripting (1.0.9)
Python Out-of-bounds Write Vulnerability (CVE-2019-12900)
SharePoint CVE-2020-1500 Vulnerability (CVE-2020-1500)
WebLogic Server-Side Request Forgery (SSRF) Vulnerability (CVE-2020-11987)
WordPress Plugin Product Import Export for WooCommerce Cross-Site Request Forgery (1.7.4)