Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Debian 9 DSA-4164-1 Moderate: Apache2 DoS Attack and Session Risks

debian
Calendar Grey April 3, 2018
Debian Logo
Essential Debian notice DSA-4165-1 outlines various security enhancements for nginx based on CVE vulnerabilities.
Several vulnerabilities have been found in the Apache HTTPD server

Summary

CVE-2017-15710

Alex Nichols and Jakob Hirsch reported that mod_authnz_ldap, if
configured with AuthLDAPCharsetConfig, could cause an of bound write
if supplied with a crafted Accept-Language header. This could
potentially be used for a Denial of Service attack.

CVE-2017-15715

Elar Lang discovered that expression specified in could
match '$' to a newline character in a malicious filename, rather
than matching only the end of the filename. This could be exploited
in environments where uploads of some files are are externally
blocked, but only by matching the trailing portion of the filename.

CVE-2018-1283

When mod_session is configured to forward its session data to CGI
applications (SessionEnv on, not the default), a remote user could
influence their content by using a "Session" header.

CVE-2018-1301

Robert Swiecki reported that a specially crafted request could have
crashed the Apache HTTP Server, due to an out of bound access after
a size ...

Read the Full Advisory

Package: apache2
CVE ID: CVE-2017-15710 CVE-2017-15715 CVE-2018-1283 CVE-2018-1301

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here