VDB
BDU%3A2021-00779
BDU%3A2021-00779
PUBLISHED
CVSS 4.300000190734863 MEDIUM
Уязвимость реализации механизма HTTP/2 веб-сервера Apache HTTP Server, позволяющая нарушителю вызвать отказ в обслуживании или привести к неверной конфигурации сервера
Risk Scores
CVSS 2.0
4.300000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Сообщество свободного программного обеспечения, Canonical Ltd., ООО «РусБИТех-Астра», Oracle Corp., Red Hat Inc., Novell Inc., Fedora Project, Apache Software Foundation, АО «НТЦ ИТ РОСА», АО «Концерн ВНИИНС» | Debian GNU/Linux, Ubuntu, Astra Linux Special Edition (запись в едином реестре российских программ №369), Instantis EnterpriseTrack, Astra Linux Common Edition (запись в едином реестре российских программ №4433), Red Hat Enterprise Linux, OpenSUSE Leap, Fedora, Astra Linux Special Edition для «Эльбрус» (запись в едином реестре российских программ №11156), JBoss Core Services, Enterprise Manager Ops Center, Sun ZFS Storage Appliance Kit, Oracle Communications Element Manager, Oracle Communications Session Report Manager, Oracle Communications Session Route Manager, Hyperion Infrastructure Technology, HTTP Server, ROSA Virtualization (запись в едином реестре российских программ №5091), ОС ОН «Стрелец» (запись в едином реестре российских программ №6177), ROSA Virtualization 3.0 (запись в едином реестре российских программ №21308) |
Timeline
- Feb 16, 2021 CVE Published
- Aug 19, 2025 CVE Updated
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Security Advisory
- Mar 19, 2026 Security Advisory
References
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00071.html url
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00081.html url
- http://packetstormsecurity.com/files/160393/Apache-2-HTTP2-Module-Concurrent-Pool-Usage.html url
- https://access.redhat.com/security/cve/cve-2020-11993 url
- https://lists.apache.org/thread.html/r5debe8f82728a00a4a68bc904dd6c35423bdfc8d601cfb4579f38bf1@%3Cdev url
- https://lists.apache.org/thread.html/r623de9b2b2433a87f3f3a15900419fc9c00c77b26936dfea4060f672@%3Cdev url
- https://lists.apache.org/thread.html/r9e9f1a7609760f0f80562eaaec2aa3c32d525c3e0fca98b475240c71@%3Cdev url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ITVFDBVM6E3JF3O7RYLRPRCH3RDRHJJY/ url
- https://nvd.nist.gov/vuln/detail/CVE-2020-11993 url
- https://wiki.astralinux.ru/astra-linux-se16-bulletin-20210611SE16 url
- https://www.debian.org/security/2020/dsa-4757 url
- https://www.oracle.com/security-alerts/cpuoct2020.html url
- https://strelets.net/patchi-i-obnovleniya-bezopasnosti#16012023 url
- https://abf.rosa.ru/advisories/ROSA-SA-2025-2900 url
- https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2020-11993 advisory
- https://lists.apache.org/thread.html/r5debe8f82728a00a4a68bc904dd6c35423bdfc8d601cfb4579f38bf1@%3Cdev.httpd.apache.org%3E advisory
- https://lists.apache.org/thread.html/r623de9b2b2433a87f3f3a15900419fc9c00c77b26936dfea4060f672@%3Cdev.httpd.apache.org%3E advisory
- https://lists.apache.org/thread.html/r9e9f1a7609760f0f80562eaaec2aa3c32d525c3e0fca98b475240c71@%3Cdev.httpd.apache.org%3E advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00068.html advisory
- https://www.oracle.com/security-alerts/cpujan2021.html advisory
…and 7 more