PT-2017-2868 · Apache+5 · Apache Http Server+5
Publicado
2017-04-11
·
Atualizado
2022-04-21
·
CVE-2017-7668
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Apache HTTP Server versions 2.2.32 through 2.4.24
Apache HTTP Server version 2.4.24
Description
The issue arises from insufficient input validation during token list parsing in the
ap find token() function. This allows an attacker to potentially cause a segmentation fault or force the ap find token() function to return an incorrect value by crafting a malicious sequence of request headers.Recommendations
For Apache HTTP Server versions 2.2.32 through 2.4.24, consider updating to a version where this issue is fixed.
For Apache HTTP Server version 2.4.24, consider updating to a version where this issue is fixed.
As a temporary workaround, consider restricting access to the
ap find token() function until a patch is available.Correção
RCE
Out of bounds Read
Buffer Over-read
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Apache Http Server
Centos
Red Hat
Suse
Ubuntu