PublicDateAtUSN: 2019-09-30 Candidate: CVE-2019-12412 PublicDate: 2020-11-19 00:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12412 http://svn.apache.org/r1866760 https://ubuntu.com/security/notices/USN-4558-1 Description: A flaw in the libapreq2 v2.07 to v2.13 multipart parser can deference a null pointer leading to a process crash. A remote attacker could send a request causing a process crash which could lead to a denial of service attack. Ubuntu-Description: It was discovered that libapreq2 did not properly sanitize the Content-Type field in certain, crafted HTTP requests. An attacker could use the vulnerability to cause libapreq2 to crash. Notes: Mitigation: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=939937 Priority: medium Discovered-by: Assigned-to: pfsmorigo CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_libapreq2: upstream_libapreq2: released (2.13-6) precise/esm_libapreq2: DNE trusty_libapreq2: ignored (out of standard support) trusty/esm_libapreq2: needed xenial_libapreq2: ignored (end of standard support, was needed) bionic_libapreq2: released (2.13-7~deb10u1build0.18.04.1) disco_libapreq2: ignored (reached end-of-life) eoan_libapreq2: ignored (reached end-of-life) focal_libapreq2: not-affected (2.13-7) groovy_libapreq2: not-affected (2.13-7) hirsute_libapreq2: not-affected (2.13-7) impish_libapreq2: not-affected (2.13-7) jammy_libapreq2: not-affected (2.13-7) devel_libapreq2: not-affected (2.13-7)