Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Debian Jessie DSA-3796-1 Moderate: Apache2 Denial Of Service

debian
Calendar Grey February 26, 2017
Debian Logo
Enhance your server's security by updating Apache2 packages to address vulnerabilities highlighted in Debian's DSA-3796-1 advisory.
Several vulnerabilities were discovered in the Apache2 HTTP server

Summary

Several vulnerabilities were discovered in the Apache2 HTTP server.

CVE-2016-0736

RedTeam Pentesting GmbH discovered that mod_session_crypto was
vulnerable to padding oracle attacks, which could allow an attacker
to guess the session cookie.

CVE-2016-2161

Maksim Malyutin discovered that malicious input to mod_auth_digest
could cause the server to crash, causing a denial of service.

CVE-2016-8743

David Dennerline, of IBM Security's X-Force Researchers, and Régis
Leroy discovered problems in the way Apache handled a broad pattern
of unusual whitespace patterns in HTTP requests. In some
configurations, this could lead to response splitting or cache
pollution vulnerabilities. To fix these issues, this update makes
Apache httpd be more strict in what HTTP requests it accepts.

If this causes problems with non-conforming clients, some checks can
be relaxed by adding the new directive "HttpProtocolOptions unsafe"
to the configuration.

This update also fixes the issue where mod...

Read the Full Advisory

Package: apache2
CVE ID: CVE-2016-0736 CVE-2016-2161 CVE-2016-8743

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here