PT-2017-3338 · Apache+5 · Apache Http Server+5

Eddie Zhu

·

Published

2017-09-18

·

Updated

2026-01-29

·

CVE-2017-9798

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.2.0 through 2.2.34 Apache HTTP Server versions 2.4.0 through 2.4.27
Description The issue allows remote attackers to read secret data from process memory under certain conditions, such as when the Limit directive can be set in a user's .htaccess file or if httpd.conf has specific misconfigurations. Attackers send an unauthenticated OPTIONS HTTP request to attempt to read secret data. This is a use-after-free issue, meaning secret data is not always sent, and the specific data depends on various factors including configuration.
Recommendations For Apache HTTP Server versions 2.2.0 through 2.2.34, apply a patch to the ap limit section function in server/core.c to block exploitation with .htaccess. For Apache HTTP Server versions 2.4.0 through 2.4.27, apply a patch to the ap limit section function in server/core.c to block exploitation with .htaccess. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2017-2477
BDU:2018-00103
CESA-2017_2882
CESA-2017_2972
CVE-2017-9798
DLA-1102-1
DSA-3980-1
ELSA-2017-2882
ELSA-2017-2972
MGASA-2018-0007
MGASA-2018-0009
OPENSUSE-SU-2018_1057-1
OPENSUSE-SU-2024:10623-1
RHSA-2017:2882
RHSA-2017:2972
RHSA-2017:3018
RHSA-2017:3113
RHSA-2017:3193
RHSA-2017:3194
RHSA-2017:3195
RHSA-2017:3240
RHSA-2017:3476
RHSA-2017:3477
RHSA-2017_2882
RHSA-2017_2972
SUSE-SU-2017:2542-1
SUSE-SU-2017:2718-1
SUSE-SU-2017:2756-1
SUSE-SU-2017:2907-1
SUSE-SU-2017_2542-1
SUSE-SU-2017_2718-1
USN-3425-1
USN-3425-2

Affected Products

Alt Linux
Apache Http Server
Centos
Red Hat
Suse
Ubuntu