In Apache HTTP Server 2.4.18-2.4.39, using fuzzed network input, the http/2 session handling could be made to read memory after being freed, during connection shutdown.
| Software | From | Fixed in |
|---|---|---|
| apache / http_server | 2.4.18 | 2.4.39.x |
| oracle / retail_xstore_point_of_service | 7.1 | 7.1.x |
| oracle / http_server | 12.2.1.3.0 | 12.2.1.3.0.x |
| oracle / enterprise_manager_ops_center | 12.3.3 | 12.3.3.x |
| oracle / enterprise_manager_ops_center | 12.4.0 | 12.4.0.x |
| oracle / instantis_enterprisetrack | 17.1 | 17.3.x |
| oracle / communications_element_manager | 8.2.0 | 8.2.0.x |
| oracle / communications_element_manager | 8.1.1 | 8.1.1.x |
| oracle / communications_element_manager | 8.1.0 | 8.1.0.x |
| oracle / communications_element_manager | 8.0.0 | 8.0.0.x |
| oracle / http_server | 12.2.1.4.0 | 12.2.1.4.0.x |
| oracle / enterprise_manager_ops_center | 12.4.0.0 | 12.4.0.0.x |