Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2024-36387

Published: July 2, 2024Last modified: July 5, 2024

Description

Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.

Severity score breakdown

ParameterValue
Base score5.4
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactLOW
Availability impactLOW
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSapache2Fixed (2.4.61-r0)
Streamapache2Fixed (2.4.61-r0)

References

Published BELL-SAs

ON THIS PAGE