PT-2016-3151 · Apache+5 · Apache Http Server+5
Maksim Malyutin
·
Published
2016-12-20
·
Updated
2021-06-06
·
CVE-2016-2161
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Apache HTTP Server versions 2.4.0 through 2.4.23
Description
The issue is caused by insufficient input validation in the mod auth digest module of the Apache HTTP Server. This can be exploited by a remote attacker to cause the server to crash. Each instance of the server continues to crash even when subsequent valid requests are made.
Recommendations
For Apache HTTP Server versions 2.4.0 through 2.4.23, consider disabling the mod auth digest module as a temporary workaround until a patch is available. Restrict access to the mod auth digest module to minimize the risk of exploitation. Update to a version that includes the fix for this issue to fully resolve it.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Apache Http Server
Centos
Red Hat
Suse
Ubuntu