Vulnerability   
Search   
    Search 191973 CVE descriptions
and 86218 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.2.2020.2165
Category:Huawei EulerOS Local Security Checks
Title:Huawei EulerOS: Security Advisory for httpd (EulerOS-SA-2020-2165)
Summary:The remote host is missing an update for the Huawei EulerOS; 'httpd' package(s) announced via the EulerOS-SA-2020-2165 advisory.
Description:Summary:
The remote host is missing an update for the Huawei EulerOS
'httpd' package(s) announced via the EulerOS-SA-2020-2165 advisory.

Vulnerability Insight:
Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via 'H2Push off' will mitigate this vulnerability for unpatched servers.(CVE-2020-9490)

Affected Software/OS:
'httpd' package(s) on Huawei EulerOS V2.0SP9.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2020-9490
https://security.netapp.com/advisory/ntap-20200814-0005/
Debian Security Information: DSA-4757 (Google Search)
https://www.debian.org/security/2020/dsa-4757
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4NKWG2EXAQQB6LMLATKZ7KLSRGCSHVAN/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ITVFDBVM6E3JF3O7RYLRPRCH3RDRHJJY/
https://security.gentoo.org/glsa/202008-04
https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2020-9490
https://www.oracle.com/security-alerts/cpuoct2020.html
https://lists.apache.org/thread.html/r9e9f1a7609760f0f80562eaaec2aa3c32d525c3e0fca98b475240c71@%3Cdev.httpd.apache.org%3E
https://lists.apache.org/thread.html/r623de9b2b2433a87f3f3a15900419fc9c00c77b26936dfea4060f672@%3Cdev.httpd.apache.org%3E
https://lists.apache.org/thread.html/r5debe8f82728a00a4a68bc904dd6c35423bdfc8d601cfb4579f38bf1@%3Cdev.httpd.apache.org%3E
SuSE Security Announcement: openSUSE-SU-2020:1285 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00068.html
SuSE Security Announcement: openSUSE-SU-2020:1293 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00071.html
SuSE Security Announcement: openSUSE-SU-2020:1792 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00081.html
https://usn.ubuntu.com/4458-1/
CopyrightCopyright (C) 2020 Greenbone Networks GmbH

This is only one of 86218 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2020 E-Soft Inc. All rights reserved.