PT-2016-3151 · Apache+5 · Apache Http Server+5
Maksim Malyutin
·
Publicado
2016-12-20
·
Atualizado
2021-06-06
·
CVE-2016-2161
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Apache HTTP Server versions 2.4.0 through 2.4.23
Description
The issue is caused by insufficient input validation in the mod auth digest module of the Apache HTTP Server. This can be exploited by a remote attacker to cause the server to crash. Each instance of the server continues to crash even when subsequent valid requests are made.
Recommendations
For Apache HTTP Server versions 2.4.0 through 2.4.23, consider disabling the mod auth digest module as a temporary workaround until a patch is available. Restrict access to the mod auth digest module to minimize the risk of exploitation. Update to a version that includes the fix for this issue to fully resolve it.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Apache Http Server
Centos
Red Hat
Suse
Ubuntu