PT-2017-2868 · Apache+5 · Apache Http Server+5
Published
2017-04-11
·
Updated
2022-04-21
·
CVE-2017-7668
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Apache HTTP Server versions 2.2.32 through 2.4.24
Apache HTTP Server version 2.4.24
Description
The issue arises from insufficient input validation during token list parsing in the
ap find token() function. This allows an attacker to potentially cause a segmentation fault or force the ap find token() function to return an incorrect value by crafting a malicious sequence of request headers.Recommendations
For Apache HTTP Server versions 2.2.32 through 2.4.24, consider updating to a version where this issue is fixed.
For Apache HTTP Server version 2.4.24, consider updating to a version where this issue is fixed.
As a temporary workaround, consider restricting access to the
ap find token() function until a patch is available.Fix
RCE
Out of bounds Read
Buffer Over-read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Apache Http Server
Centos
Red Hat
Suse
Ubuntu