Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Kawahara Masashi

#42006of 55,077
6.5Total CVSS
Vulnerabilities · 1
PT-2017-3746
6.5
2017-10-19
Apache · Httpd · CVE-2017-12171
Name of the Vulnerable Software and Affected Versions: httpd version 2.2.15-60 Description: A regression was found in httpd, causing comments in the "Allow" and "Deny" configuration lines to be parsed incorrectly. This issue is related to the use of memory after it has been freed when processing comments in the Allow and Deny lines of the Limit directive in the .htaccess configuration file. Exploitation of this issue may allow a remote attacker to cause a crash of the httpd child process or gain access to restricted HTTP resources. Recommendations: For httpd version 2.2.15-60, consider updating to a newer version that includes a fix for this issue, as the current version may allow unintended access to restricted HTTP resources due to incorrect parsing of comments in configuration lines.