PT-2018-3115 · Apache+5 · Apache Httpd+6

Alex Nichols

+1

·

Publicado

2018-03-21

·

Atualizado

2021-06-06

·

CVE-2017-15710

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache httpd versions 2.0.23 through 2.0.65 Apache httpd versions 2.2.0 through 2.2.34 Apache httpd versions 2.4.0 through 2.4.29
Description The issue is related to the mod authnz ldap component in Apache httpd, specifically when configured with AuthLDAPCharsetConfig. It uses the Accept-Language header value to determine the correct charset encoding for user credential verification. If the header value is not found in the charset conversion table, it is truncated to a two-character value. A header value with less than two characters can cause an out-of-bounds write of a NUL byte to a memory location, potentially leading to a Denial of Service attack, although this is unlikely. In most cases, the memory is already reserved for future use, and the issue has no effect.
Recommendations For Apache httpd versions 2.0.23 through 2.0.65, consider disabling the AuthLDAPCharsetConfig to prevent the issue until a patch is available. For Apache httpd versions 2.2.0 through 2.2.34, consider disabling the AuthLDAPCharsetConfig to prevent the issue until a patch is available. For Apache httpd versions 2.4.0 through 2.4.29, consider disabling the AuthLDAPCharsetConfig to prevent the issue until a patch is available. As a temporary workaround, consider restricting access to the Accept-Language header to minimize the risk of exploitation.

Correção

DoS

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-1519
BDU:2019-04105
CESA-2020_1121
CVE-2017-15710
DLA-1389-1
DSA-4164-1
MGASA-2018-0460
RHSA-2018:3558
RHSA-2019:0367
RHSA-2020:1121
RHSA-2020_1121
SUSE-SU-2018:0879-1
SUSE-SU-2018:0901-1
SUSE-SU-2018:1079-1
SUSE-SU-2018:1161-1
SUSE-SU-2018:1161-2
SUSE-SU-2018_0879-1
SUSE-SU-2018_0901-1
SUSE-SU-2018_1079-1
SUSE-SU-2018_1161-1
SUSE-SU-2018_1161-2
USN-3627-1
USN-3627-2
USN-3937-2

Produtos afetados

Alt Linux
Apache Http Server
Apache Httpd
Centos
Red Hat
Suse
Ubuntu