PT-2018-3116 · Apache+5 · Apache Httpd+6

Published

2018-03-21

·

Updated

2021-06-06

·

CVE-2017-15715

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache httpd versions 2.4.0 through 2.4.29
Description The issue arises from the expression specified in FilesMatch being able to match '$' to a newline character in a malicious filename, rather than matching only the end of the filename. This could be exploited in environments where uploads of some files are externally blocked, but only by matching the trailing portion of the filename. The vulnerability exists due to insufficient input validation, which may allow a remote attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For Apache httpd versions 2.4.0 through 2.4.29, consider updating to a version where this issue is fixed, as the current version may allow malicious filenames to bypass external blocking by matching the trailing portion of the filename. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1519
BDU:2019-04106
CESA-2020_3958
CVE-2017-15715
DSA-4164-1
MGASA-2018-0460
RHSA-2018:3558
RHSA-2019:0367
RHSA-2020:3958
RHSA-2020_3958
SUSE-SU-2018:0879-1
SUSE-SU-2018:0901-1
SUSE-SU-2018:1161-1
SUSE-SU-2018:1161-2
USN-3627-1
USN-3627-2

Affected Products

Alt Linux
Apache Http Server
Apache Httpd
Centos
Red Hat
Suse
Ubuntu