PT-2016-3151 · Apache+5 · Apache Http Server+5

Maksim Malyutin

·

Publicado

2016-12-20

·

Atualizado

2021-06-06

·

CVE-2016-2161

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.4.0 through 2.4.23
Description The issue is caused by insufficient input validation in the mod auth digest module of the Apache HTTP Server. This can be exploited by a remote attacker to cause the server to crash. Each instance of the server continues to crash even when subsequent valid requests are made.
Recommendations For Apache HTTP Server versions 2.4.0 through 2.4.23, consider disabling the mod auth digest module as a temporary workaround until a patch is available. Restrict access to the mod auth digest module to minimize the risk of exploitation. Update to a version that includes the fix for this issue to fully resolve it.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-1655
BDU:2017-01805
CESA-2017_0906
CVE-2016-2161
DSA-3796-1
MGASA-2018-0007
RHSA-2017:0906
RHSA-2017:1161
RHSA-2017:1413
RHSA-2017:1414
RHSA-2017_0906
SUSE-SU-2017:0729-1
SUSE-SU-2017:0797-1
SUSE-SU-2017:0801-1
SUSE-SU-2017_0729-1
USN-3279-1

Produtos afetados

Alt Linux
Apache Http Server
Centos
Red Hat
Suse
Ubuntu