Vulnerability Description
A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause mod_ssl to enter a loop leading to a denial of service. This bug can be only triggered with Apache HTTP Server version 2.4.37 when using OpenSSL version 1.1.1 or later, due to an interaction in changes to handling of renegotiation attempts.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Http Server | 2.4.37 |
| Openssl | Openssl | >= 1.1.1 |
| Oracle | Enterprise Manager Ops Center | 12.3.3 |
| Oracle | Hospitality Guest Access | 4.2.0 |
| Oracle | Instantis Enterprisetrack | 17.1 |
| Oracle | Retail Xstore Point Of Service | 7.0 |
References
- http://www.securityfocus.com/bid/106743Third Party AdvisoryVDB Entry
- https://httpd.apache.org/security/vulnerabilities_24.htmlVendor Advisory
- https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cd
- https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e10
- https://lists.apache.org/thread.html/r03ee478b3dda3e381fd6189366fa7af97c980d2f60
- https://lists.apache.org/thread.html/r06f0d87ebb6d59ed8379633f36f72f5b1f79cadfda
- https://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37
- https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f8
- https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa
- https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0
- https://lists.apache.org/thread.html/rd2fb621142e7fa187cfe12d7137bf66e7234abcbbc
- https://lists.apache.org/thread.html/rd336919f655b7ff309385e34a143e41c503e133da8
- https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cac
- https://lists.apache.org/thread.html/re473305a65b4db888e3556e4dae10c2a04ee89dcff
- https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90b
FAQ
What is CVE-2019-0190?
CVE-2019-0190 is a vulnerability with a CVSS score of 7.5 (HIGH). A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause mod_ssl to enter a loop leading to a denial of service. This bu...
How severe is CVE-2019-0190?
CVE-2019-0190 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-0190?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Http Server, Openssl Openssl, Oracle Enterprise Manager Ops Center, Oracle Hospitality Guest Access, Oracle Instantis Enterprisetrack.