In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer when third-party modules call ap_hook_process_connection() during an HTTP request to an HTTPS port.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Http_server | Apache | 2.2.0 (including) | 2.2.0 (including) |
Http_server | Apache | 2.2.2 (including) | 2.2.2 (including) |
Http_server | Apache | 2.2.3 (including) | 2.2.3 (including) |
Http_server | Apache | 2.2.11 (including) | 2.2.11 (including) |
Http_server | Apache | 2.2.12 (including) | 2.2.12 (including) |
Http_server | Apache | 2.2.13 (including) | 2.2.13 (including) |
Http_server | Apache | 2.2.14 (including) | 2.2.14 (including) |
Http_server | Apache | 2.2.15 (including) | 2.2.15 (including) |
Http_server | Apache | 2.2.16 (including) | 2.2.16 (including) |
Http_server | Apache | 2.2.17 (including) | 2.2.17 (including) |
Http_server | Apache | 2.2.18 (including) | 2.2.18 (including) |
Http_server | Apache | 2.2.19 (including) | 2.2.19 (including) |
Http_server | Apache | 2.2.20 (including) | 2.2.20 (including) |
Http_server | Apache | 2.2.21 (including) | 2.2.21 (including) |
Http_server | Apache | 2.2.22 (including) | 2.2.22 (including) |
Http_server | Apache | 2.2.23 (including) | 2.2.23 (including) |
Http_server | Apache | 2.2.24 (including) | 2.2.24 (including) |
Http_server | Apache | 2.2.25 (including) | 2.2.25 (including) |
Http_server | Apache | 2.2.26 (including) | 2.2.26 (including) |
Http_server | Apache | 2.2.27 (including) | 2.2.27 (including) |
Http_server | Apache | 2.2.29 (including) | 2.2.29 (including) |
Http_server | Apache | 2.2.30 (including) | 2.2.30 (including) |
Http_server | Apache | 2.2.31 (including) | 2.2.31 (including) |
Http_server | Apache | 2.2.32 (including) | 2.2.32 (including) |
Http_server | Apache | 2.4.1 (including) | 2.4.1 (including) |
Http_server | Apache | 2.4.2 (including) | 2.4.2 (including) |
Http_server | Apache | 2.4.10 (including) | 2.4.10 (including) |
Http_server | Apache | 2.4.12 (including) | 2.4.12 (including) |
Http_server | Apache | 2.4.16 (including) | 2.4.16 (including) |
Http_server | Apache | 2.4.17 (including) | 2.4.17 (including) |
Http_server | Apache | 2.4.18 (including) | 2.4.18 (including) |
Http_server | Apache | 2.4.20 (including) | 2.4.20 (including) |
Http_server | Apache | 2.4.23 (including) | 2.4.23 (including) |
Http_server | Apache | 2.4.25 (including) | 2.4.25 (including) |
Apache2 | Ubuntu | devel | * |
Apache2 | Ubuntu | trusty | * |
Apache2 | Ubuntu | upstream | * |
Apache2 | Ubuntu | xenial | * |
Apache2 | Ubuntu | yakkety | * |
Apache2 | Ubuntu | zesty | * |
JBoss Core Services on RHEL 6 | RedHat | jbcs-httpd24-httpd-0:2.4.23-125.jbcs.el6 | * |
JBoss Core Services on RHEL 6 | RedHat | jbcs-httpd24-mod_bmx-0:0.9.6-15.GA.jbcs.el6 | * |
JBoss Core Services on RHEL 6 | RedHat | jbcs-httpd24-mod_cluster-native-0:1.3.8-1.Final_redhat_1.jbcs.el6 | * |
JBoss Core Services on RHEL 7 | RedHat | jbcs-httpd24-httpd-0:2.4.23-125.jbcs.el7 | * |
JBoss Core Services on RHEL 7 | RedHat | jbcs-httpd24-mod_bmx-0:0.9.6-15.GA.jbcs.el7 | * |
JBoss Core Services on RHEL 7 | RedHat | jbcs-httpd24-mod_cluster-native-0:1.3.8-1.Final_redhat_1.jbcs.el7 | * |
Red Hat Enterprise Linux 6 | RedHat | httpd-0:2.2.15-60.el6_9.5 | * |
Red Hat Enterprise Linux 6.7 Extended Update Support | RedHat | httpd-0:2.2.15-47.el6_7.5 | * |
Red Hat Enterprise Linux 7 | RedHat | httpd-0:2.4.6-67.el7_4.2 | * |
Red Hat Enterprise Linux 7.2 Extended Update Support | RedHat | httpd-0:2.4.6-40.el7_2.6 | * |
Red Hat Enterprise Linux 7.3 Extended Update Support | RedHat | httpd-0:2.4.6-45.el7_3.5 | * |
Red Hat JBoss Core Services 1 | RedHat | httpd | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | RedHat | httpd24-httpd-0:2.4.25-9.el6.1 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | RedHat | httpd24-httpd-0:2.4.25-9.el6.1 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | httpd24-httpd-0:2.4.25-9.el7.1 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS | RedHat | httpd24-httpd-0:2.4.25-9.el7.1 | * |