Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
| Vendor | Product | Versions |
|---|---|---|
| apache | http_server | 2.4.0, 2.4.67 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| apache | http | cert_advisory | 90% |
| oracle | oracle communications | cert_advisory | 90% |
| oracle | solaris | cert_advisory | 90% |
Updated affected versions to include 2.4.67 and noted that the patch is now unavailable.
Updated severity to HIGH, marked exploit as available, and noted that the vulnerability is actively exploited.
Updated severity to HIGH and CVSS estimate to 7.5, and marked the vulnerability as actively exploited.
Initial creation