Update Apache to address multiple vulnerabilities

This message is intended for U-M IT staff who are responsible for university systems running Apache server software, and will be of interest to anyone using Apache.

Summary

A critical vulnerability in Apache HTTP Server version 2.4.66's HTTP/2 module can lead to unauthenticated Remote Code Execution (RCE) and Denial of Service (DoS) attacks. Users should update vulnerable versions of Apache software to version 2.4.67 or later, or apply vendor-supplied patches that address this vulnerability now.

Problem

The Apache Software Foundation (ASF) has released security updates to address several security vulnerabilities in the HTTP Server, including a severe vulnerability that could potentially lead to remote code execution (RCE).

Threats

This vulnerability could lead to unauthenticated Remote Code Execution (RCE) and Denial of Service (DoS) attacks on affected Apache servers. Proof of concept code exists for RCE and DoS attacks.

Affected Systems

This issue affects Apache HTTP Server version 2.4.66.

Detection

This vulnerability is present in Apache HTTP Server 2.4.66. 

Action Items

Immediately update vulnerable versions of Apache software to a non-vulnerable version, either by updating to Apache version 2.4.67 or later, or applying vendor-supplied patches that address this vulnerability now. 

The need for immediate action supersedes the remediation timeframes in Vulnerability Management (DS-21).

Technical Details

A double-free vulnerability occurs when two calls to the same memory block are made in rapid succession, creating possible corruption in the memory management data. This can cause the program to crash (Denial of Service), or in some cases for a threat actor to send their own code resulting in Remote Code Execution (RCE).

Questions, Concerns, Reports

Please contact ITS Information Assurance through the ITS Service Center.