PT-2017-2868 · Apache+5 · Apache Http Server+5

Published

2017-04-11

·

Updated

2022-04-21

·

CVE-2017-7668

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.2.32 through 2.4.24 Apache HTTP Server version 2.4.24
Description The issue arises from insufficient input validation during token list parsing in the ap find token() function. This allows an attacker to potentially cause a segmentation fault or force the ap find token() function to return an incorrect value by crafting a malicious sequence of request headers.
Recommendations For Apache HTTP Server versions 2.2.32 through 2.4.24, consider updating to a version where this issue is fixed. For Apache HTTP Server version 2.4.24, consider updating to a version where this issue is fixed. As a temporary workaround, consider restricting access to the ap find token() function until a patch is available.

Fix

RCE

Out of bounds Read

Buffer Over-read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1783
BDU:2017-02150
CESA-2017_2479
CVE-2017-7668
DLA-1009-1
DSA-3896-1
MGASA-2018-0007
RHSA-2017:2479
RHSA-2017:2483
RHSA-2017:3193
RHSA-2017:3194
RHSA-2017_2479
SUSE-SU-2017:2907-1
USN-3340-1
USN-3373-1

Affected Products

Alt Linux
Apache Http Server
Centos
Red Hat
Suse
Ubuntu