Vulnerability Description
A flaw in the libapreq2 v2.07 to v2.13 multipart parser can deference a null pointer leading to a process crash. A remote attacker could send a request causing a process crash which could lead to a denial of service attack.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Libapreq2 | >= 2.07, <= 2.13 |
Related Weaknesses (CWE)
References
- https://bugs.debian.org/939937Mailing ListThird Party Advisory
- https://lists.apache.org/thread.html/rce5814279a615d4a17c870a3c5b77f57975874d382Mailing ListVendor Advisory
- https://bugs.debian.org/939937Mailing ListThird Party Advisory
- https://lists.apache.org/thread.html/rce5814279a615d4a17c870a3c5b77f57975874d382Mailing ListVendor Advisory
FAQ
What is CVE-2019-12412?
CVE-2019-12412 is a vulnerability with a CVSS score of 7.5 (HIGH). A flaw in the libapreq2 v2.07 to v2.13 multipart parser can deference a null pointer leading to a process crash. A remote attacker could send a request causing a process crash which could lead to a de...
How severe is CVE-2019-12412?
CVE-2019-12412 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-12412?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Libapreq2.