PT-2016-3151 · Apache+5 · Apache Http Server+5

Maksim Malyutin

·

Published

2016-12-20

·

Updated

2021-06-06

·

CVE-2016-2161

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.4.0 through 2.4.23
Description The issue is caused by insufficient input validation in the mod auth digest module of the Apache HTTP Server. This can be exploited by a remote attacker to cause the server to crash. Each instance of the server continues to crash even when subsequent valid requests are made.
Recommendations For Apache HTTP Server versions 2.4.0 through 2.4.23, consider disabling the mod auth digest module as a temporary workaround until a patch is available. Restrict access to the mod auth digest module to minimize the risk of exploitation. Update to a version that includes the fix for this issue to fully resolve it.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1655
BDU:2017-01805
CESA-2017_0906
CVE-2016-2161
DSA-3796-1
MGASA-2018-0007
RHSA-2017:0906
RHSA-2017:1161
RHSA-2017:1413
RHSA-2017:1414
RHSA-2017_0906
SUSE-SU-2017:0729-1
SUSE-SU-2017:0797-1
SUSE-SU-2017:0801-1
SUSE-SU-2017_0729-1
USN-3279-1

Affected Products

Alt Linux
Apache Http Server
Centos
Red Hat
Suse
Ubuntu