PT-2017-3338 · Apache+5 · Apache Http Server+5

Eddie Zhu

·

Publicado

2017-09-18

·

Atualizado

2026-01-29

·

CVE-2017-9798

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.2.0 through 2.2.34 Apache HTTP Server versions 2.4.0 through 2.4.27
Description The issue allows remote attackers to read secret data from process memory under certain conditions, such as when the Limit directive can be set in a user's .htaccess file or if httpd.conf has specific misconfigurations. Attackers send an unauthenticated OPTIONS HTTP request to attempt to read secret data. This is a use-after-free issue, meaning secret data is not always sent, and the specific data depends on various factors including configuration.
Recommendations For Apache HTTP Server versions 2.2.0 through 2.2.34, apply a patch to the ap limit section function in server/core.c to block exploitation with .htaccess. For Apache HTTP Server versions 2.4.0 through 2.4.27, apply a patch to the ap limit section function in server/core.c to block exploitation with .htaccess. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2025_16880
ALT-PU-2017-2477
BDU:2018-00103
CESA-2017_2882
CESA-2017_2972
CVE-2017-9798
DLA-1102-1
DSA-3980-1
ELSA-2017-2882
ELSA-2017-2972
MGASA-2018-0007
MGASA-2018-0009
OPENSUSE-SU-2018_1057-1
OPENSUSE-SU-2024:10623-1
RHSA-2017:2882
RHSA-2017:2972
RHSA-2017:3018
RHSA-2017:3113
RHSA-2017:3193
RHSA-2017:3194
RHSA-2017:3195
RHSA-2017:3240
RHSA-2017:3476
RHSA-2017:3477
RHSA-2017_2882
RHSA-2017_2972
SUSE-SU-2017:2542-1
SUSE-SU-2017:2718-1
SUSE-SU-2017:2756-1
SUSE-SU-2017:2907-1
SUSE-SU-2017_2542-1
SUSE-SU-2017_2718-1
USN-3425-1
USN-3425-2

Produtos afetados

Alt Linux
Apache Http Server
Centos
Red Hat
Suse
Ubuntu