2021-02-04 12:00:40 +00:00
{
"CVE_data_meta" : {
2021-06-10 08:09:33 +01:00
"ASSIGNER" : "security@apache.org" ,
2021-02-04 12:00:40 +00:00
"ID" : "CVE-2021-26690" ,
2021-06-10 08:09:33 +01:00
"STATE" : "PUBLIC" ,
"TITLE" : "mod_session NULL pointer dereference"
2021-02-04 12:00:40 +00:00
} ,
2021-06-10 08:09:33 +01:00
"affects" : {
"vendor" : {
"vendor_data" : [
{
"product" : {
"product_data" : [
{
"product_name" : "Apache HTTP Server" ,
"version" : {
"version_data" : [
{
"version_affected" : "=" ,
"version_name" : "2.4" ,
"version_value" : "2.4.46"
} ,
{
"version_affected" : "=" ,
"version_name" : "2.4" ,
"version_value" : "2.4.43"
} ,
{
"version_affected" : "=" ,
"version_name" : "2.4" ,
"version_value" : "2.4.41"
} ,
{
"version_affected" : "=" ,
"version_name" : "2.4" ,
"version_value" : "2.4.39"
} ,
{
"version_affected" : "=" ,
"version_name" : "2.4" ,
"version_value" : "2.4.38"
} ,
{
"version_affected" : "=" ,
"version_name" : "2.4" ,
"version_value" : "2.4.37"
} ,
{
"version_affected" : "=" ,
"version_name" : "2.4" ,
"version_value" : "2.4.35"
} ,
{
"version_affected" : "=" ,
"version_name" : "2.4" ,
"version_value" : "2.4.34"
} ,
{
"version_affected" : "=" ,
"version_name" : "2.4" ,
"version_value" : "2.4.33"
} ,
{
"version_affected" : "=" ,
"version_name" : "2.4" ,
"version_value" : "2.4.29"
} ,
{
"version_affected" : "=" ,
"version_name" : "2.4" ,
"version_value" : "2.4.28"
} ,
{
"version_affected" : "=" ,
"version_name" : "2.4" ,
"version_value" : "2.4.27"
} ,
{
"version_affected" : "=" ,
"version_name" : "2.4" ,
"version_value" : "2.4.26"
} ,
{
"version_affected" : "=" ,
"version_name" : "2.4" ,
"version_value" : "2.4.25"
} ,
{
"version_affected" : "=" ,
"version_name" : "2.4" ,
"version_value" : "2.4.23"
} ,
{
"version_affected" : "=" ,
"version_name" : "2.4" ,
"version_value" : "2.4.20"
} ,
{
"version_affected" : "=" ,
"version_name" : "2.4" ,
"version_value" : "2.4.18"
} ,
{
"version_affected" : "=" ,
"version_name" : "2.4" ,
"version_value" : "2.4.17"
} ,
{
"version_affected" : "=" ,
"version_name" : "2.4" ,
"version_value" : "2.4.16"
} ,
{
"version_affected" : "=" ,
"version_name" : "2.4" ,
"version_value" : "2.4.12"
} ,
{
"version_affected" : "=" ,
"version_name" : "2.4" ,
"version_value" : "2.4.10"
} ,
{
"version_affected" : "=" ,
"version_name" : "2.4" ,
"version_value" : "2.4.9"
} ,
{
"version_affected" : "=" ,
"version_name" : "2.4" ,
"version_value" : "2.4.7"
} ,
{
"version_affected" : "=" ,
"version_name" : "2.4" ,
"version_value" : "2.4.6"
} ,
{
"version_affected" : "=" ,
"version_name" : "2.4" ,
"version_value" : "2.4.4"
} ,
{
"version_affected" : "=" ,
"version_name" : "2.4" ,
"version_value" : "2.4.3"
} ,
{
"version_affected" : "=" ,
"version_name" : "2.4" ,
"version_value" : "2.4.2"
} ,
{
"version_affected" : "=" ,
"version_name" : "2.4" ,
"version_value" : "2.4.1"
} ,
{
"version_affected" : "=" ,
"version_name" : "2.4" ,
"version_value" : "2.4.0"
}
]
}
}
]
} ,
"vendor_name" : "Apache Software Foundation"
}
]
}
} ,
"credit" : [
{
"lang" : "eng" ,
"value" : "This issue was discovered and reported by GHSL team member @antonio-morales (Antonio Morales)"
}
] ,
"data_format" : "MITRE" ,
"data_type" : "CVE" ,
"data_version" : "4.0" ,
2021-02-04 12:00:40 +00:00
"description" : {
"description_data" : [
{
"lang" : "eng" ,
2021-06-10 08:09:33 +01:00
"value" : "Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL pointer dereference and crash, leading to a possible Denial Of Service"
}
]
} ,
"generator" : {
"engine" : "Vulnogram 0.0.9"
} ,
"impact" : [
{
"other" : "low"
}
] ,
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng" ,
"value" : "mod_session NULL pointer dereference"
}
]
2021-02-04 12:00:40 +00:00
}
]
2021-06-10 08:09:33 +01:00
} ,
"references" : {
"reference_data" : [
{
2021-06-10 08:00:57 +00:00
"refsource" : "MISC" ,
"url" : "http://httpd.apache.org/security/vulnerabilities_24.html" ,
"name" : "http://httpd.apache.org/security/vulnerabilities_24.html"
2021-06-10 08:09:33 +01:00
} ,
{
2021-06-10 08:00:57 +00:00
"refsource" : "MISC" ,
"url" : "https://lists.apache.org/thread.html/re026d3da9d7824bd93b9f871c0fdda978d960c7e62d8c43cba8d0bf3%40%3Ccvs.httpd.apache.org%3E" ,
"name" : "https://lists.apache.org/thread.html/re026d3da9d7824bd93b9f871c0fdda978d960c7e62d8c43cba8d0bf3%40%3Ccvs.httpd.apache.org%3E"
2021-06-10 11:00:51 +00:00
} ,
{
"refsource" : "MLIST" ,
"name" : "[httpd-announce] 20210609 CVE-2021-26690: mod_session NULL pointer dereference" ,
"url" : "https://lists.apache.org/thread.html/rae406c1d19c0dfd3103c96923dadac2af1cd0bad6905ab1ede153865@%3Cannounce.httpd.apache.org%3E"
} ,
{
"refsource" : "MLIST" ,
"name" : "[httpd-dev] 20210610 Re: svn commit: r1890598 - in /httpd/site/trunk/content/security/json: CVE-2019-17567.json CVE-2020-13938.json CVE-2020-13950.json CVE-2020-35452.json CVE-2021-26690.json CVE-2021-26691.json CVE-2021-30641.json CVE-2021-31618.json" ,
"url" : "https://lists.apache.org/thread.html/r7f2b70b621651548f4b6f027552f1dd91705d7111bb5d15cda0a68dd@%3Cdev.httpd.apache.org%3E"
2021-06-10 15:00:56 +00:00
} ,
{
"refsource" : "MLIST" ,
"name" : "[oss-security] 20210609 CVE-2021-26690: Apache httpd: mod_session NULL pointer dereference" ,
"url" : "http://www.openwall.com/lists/oss-security/2021/06/10/6"
2021-07-02 12:00:54 +00:00
} ,
2021-07-09 11:00:48 +00:00
{
"refsource" : "MLIST" ,
"name" : "[debian-lts-announce] 20210709 [SECURITY] [DLA 2706-1] apache2 security update" ,
"url" : "https://lists.debian.org/debian-lts-announce/2021/07/msg00006.html"
2021-07-09 12:00:56 +00:00
} ,
{
"refsource" : "DEBIAN" ,
"name" : "DSA-4937" ,
"url" : "https://www.debian.org/security/2021/dsa-4937"
2021-07-17 08:01:03 +00:00
} ,
{
"refsource" : "GENTOO" ,
"name" : "GLSA-202107-38" ,
"url" : "https://security.gentoo.org/glsa/202107-38"
2021-09-20 16:00:59 +00:00
} ,
{
"refsource" : "FEDORA" ,
"name" : "FEDORA-2021-dce7e7738e" ,
"url" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7TJOHX7RHWD/"
2021-09-25 01:00:54 +00:00
} ,
{
"refsource" : "FEDORA" ,
"name" : "FEDORA-2021-e3f6dd670d" ,
"url" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3HDQK4VP45R/"
2021-10-19 14:23:14 -07:00
} ,
{
2021-10-20 11:02:08 +00:00
"url" : "https://www.oracle.com/security-alerts/cpuoct2021.html" ,
"refsource" : "MISC" ,
"name" : "https://www.oracle.com/security-alerts/cpuoct2021.html"
} ,
{
"refsource" : "CONFIRM" ,
"name" : "https://security.netapp.com/advisory/ntap-20210702-0001/" ,
"url" : "https://security.netapp.com/advisory/ntap-20210702-0001/"
2021-06-10 08:09:33 +01:00
}
]
} ,
"source" : {
"discovery" : "UNKNOWN"
2021-02-04 12:00:40 +00:00
}
2021-06-10 08:00:57 +00:00
}