PT-2016-3150 · Apache+5 · Apache Http Server+5

David Dennerline

+1

·

Published

2016-12-20

·

Updated

2022-09-07

·

CVE-2016-8743

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions prior to 2.2.32 and 2.4.25
Description The issue is related to the improper handling of data by the Apache HTTP Server, which was liberal in accepting whitespace from requests and sending it in response lines and headers. This behavior poses a security concern when the server participates in a chain of proxies or interacts with back-end application servers, potentially leading to request smuggling, response splitting, and cache pollution.
Recommendations For versions prior to 2.2.32 and 2.4.25, update to version 2.2.32 or 2.4.25, or later, which includes the new directive HttpProtocolOptions Strict to address these defects. As a temporary workaround, consider using the HttpProtocolOptions directive with the Strict option to enforce stricter HTTP protocol compliance. Restrict access to the server until the update can be applied to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1655
BDU:2017-01804
CESA-2017_0906
CESA-2017_1721
CVE-2016-8743
DLA-841-1
DLA-841-2
DSA-3796-1
DSA-3796-2
MGASA-2018-0007
OPENSUSE-SU-2018_2856-1
RHSA-2017:0906
RHSA-2017:1161
RHSA-2017:1413
RHSA-2017:1414
RHSA-2017:1721
RHSA-2017_0906
RHSA-2017_1721
SUSE-SU-2017:0729-1
SUSE-SU-2017:0797-1
SUSE-SU-2017:0801-1
SUSE-SU-2018:2554-1
SUSE-SU-2018:2815-1
SUSE-SU-2018:2815-2
USN-3279-1
USN-3373-1

Affected Products

Alt Linux
Apache Http Server
Centos
Red Hat
Suse
Ubuntu