imPC@ndo IT

Tracker / CVE-2019-10082

CVE-2019-10082

Critical 9.1

In Apache HTTP Server 2.4.18-2.4.39, using fuzzed network input, the http/2 session handling could be made to read memory after being freed, during connection shutdown.

Affected products and versions

apache http_server · 2.4.18 → 2.4.39
oracle communications_element_manager
oracle enterprise_manager_ops_center
oracle http_server
oracle instantis_enterprisetrack · 17.1 → 17.3
oracle retail_xstore_point_of_service

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References