Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Debian: DSA-3896-1 Moderate: Apache HTTPD Authentication Bypass and DoS

debian
Calendar Grey June 22, 2017
Debian Logo
Upgrade to Apache 2 to resolve critical vulnerabilities including authentication bypass flaws and denial of service threats.
Several vulnerabilities have been found in the Apache HTTPD server

Summary

CVE-2017-3167

Emmanuel Dreyfus reported that the use of ap_get_basic_auth_pw() by
third-party modules outside of the authentication phase may lead to
authentication requirements being bypassed.

CVE-2017-3169

Vasileios Panopoulos of AdNovum Informatik AG discovered that
mod_ssl may dereference a NULL pointer when third-party modules call
ap_hook_process_connection() during an HTTP request to an HTTPS port
leading to a denial of service.

CVE-2017-7659

Robert Swiecki reported that a specially crafted HTTP/2 request
could cause mod_http2 to dereference a NULL pointer and crash the
server process.

CVE-2017-7668

Javier Jimenez reported that the HTTP strict parsing contains a
flaw leading to a buffer overread in ap_find_token(). A remote
attacker can take advantage of this flaw by carefully crafting a
sequence of request headers to cause a segmentation fault, or to
force ap_find_token() to return an incorrect value.

CVE-2017-7679

ChenQin and Hann...

Read the Full Advisory

Package: apache2
CVE ID: CVE-2017-3167 CVE-2017-3169 CVE-2017-7659 CVE-2017-7668

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here