DEBIAN-CVE-2024-36387

Source
https://security-tracker.debian.org/tracker/DEBIAN-CVE-2024-36387
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-36387.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2024-36387
Upstream
Published
2024-07-01T19:15:03Z
Modified
2025-09-19T07:35:07.229900Z
Summary
[none]
Details

Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.

References

Affected packages

Debian:11 / apache2

Package

Name
apache2
Purl
pkg:deb/debian/apache2?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.61-1~deb11u1

Affected versions

2.*

2.4.48-3.1
2.4.48-3.1+deb11u1
2.4.48-4
2.4.49-1~bpo10+1
2.4.49-1~deb11u1
2.4.49-1~deb11u2
2.4.49-1~deb11u3
2.4.49-1
2.4.49-2
2.4.49-3
2.4.49-4
2.4.50-1~deb11u1
2.4.50-1
2.4.51-1~bpo10+1
2.4.51-1~bpo10+2
2.4.51-1~deb11u1
2.4.51-1
2.4.51-2
2.4.52-1~bpo10+1
2.4.52-1~deb11u1
2.4.52-1~deb11u2
2.4.52-1
2.4.52-2
2.4.52-3
2.4.53-1~deb11u1
2.4.53-1
2.4.53-2~bpo10+1
2.4.53-2
2.4.54-1~deb11u1
2.4.54-1
2.4.54-2
2.4.54-3
2.4.54-4
2.4.54-5
2.4.55-1
2.4.56-1~deb11u1
2.4.56-1~deb11u2
2.4.56-1
2.4.56-2
2.4.57-1
2.4.57-2
2.4.57-3
2.4.58-1
2.4.59-1~deb10u1
2.4.59-1~deb11u1
2.4.59-1~deb12u1
2.4.59-1
2.4.59-2
2.4.60-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / apache2

Package

Name
apache2
Purl
pkg:deb/debian/apache2?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.61-1~deb12u1

Affected versions

2.*

2.4.57-2
2.4.57-3
2.4.58-1
2.4.59-1~deb10u1
2.4.59-1~deb11u1
2.4.59-1~deb12u1
2.4.59-1
2.4.59-2
2.4.60-1
2.4.61-1~deb11u1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / apache2

Package

Name
apache2
Purl
pkg:deb/debian/apache2?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.60-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14 / apache2

Package

Name
apache2
Purl
pkg:deb/debian/apache2?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.60-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}