CVE-2019-10097: mod_remoteip stack buffer overflow and NULL pointer dereference

Severity: Moderate

Vendor: The Apache Software Foundation

Versions Affected:
httpd 2.4.32 to 2.4.39

When mod_remoteip was configured to use a trusted intermediary proxy
server using the "PROXY" protocol, a specially crafted PROXY header
could trigger a stack buffer overflow or NULL pointer deference.
This vulnerability could only be triggered by a trusted proxy and not
by untrusted HTTP clients.

PROXY protocol support was added to mod_remoteip in release 2.4.33.

All httpd users should upgrade to 2.4.41 or later.

The issue was discovered by Daniel McCarney <> Let's 
Encrypt / Internet Security Research Group (ISRG)


Reply via email to