7.5
CVSSv3

CVE-2019-12412

Published: 19/11/2020 Updated: 30/11/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

A flaw in the libapreq2 v2.07 to v2.13 multipart parser can deference a null pointer leading to a process crash. A remote attacker could send a request causing a process crash which could lead to a denial of service attack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache libapreq2

Vendor Advisories

Max Kellermann reported a NULL pointer dereference flaw in libapreq2, a generic Apache request library, allowing a remote attacker to cause a denial of service against an application using the library (application crash) if an invalid nested multipart body is processed For the oldstable distribution (stretch), this problem has been fixed in versio ...
Remotely exploitable null pointer dereference bug (CVE-2019-12412) ...