Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Debian 7: DLA-1009-1 Critical: Apache2 Denial Of Service Security Update

debian lts
Calendar Grey July 2, 2017
Dist Debian Esm H88
Several vulnerabilities identified in Apache2 HTTPD server addressed in the security patch for Debian 7 Wheezy. Upgrade advised.
Several vulnerabilities have been found in the Apache HTTPD server

Summary

CVE-2017-3167

Emmanuel Dreyfus reported that the use of ap_get_basic_auth_pw() by
third-party modules outside of the authentication phase may lead to
authentication requirements being bypassed.

CVE-2017-3169

Vasileios Panopoulos of AdNovum Informatik AG discovered that
mod_ssl may dereference a NULL pointer when third-party modules call
ap_hook_process_connection() during an HTTP request to an HTTPS port
leading to a denial of service.

CVE-2017-7668

Javier Jimenez reported that the HTTP strict parsing contains a flaw
leading to a buffer overread in ap_find_token(). A remote attacker
can take advantage of this flaw by carefully crafting a sequence of
request headers to cause a segmentation fault, or to force
ap_find_token() to return an incorrect value.

CVE-2017-7679

ChenQin and Hanno Boeck reported that mod_mime can read one byte
past the end of a buffer when sending a malicious Content-Type
response header.

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

<pre><font face="Courier">Package: apache2
Version: 2.2.22-13+deb7u9
CVE ID: CVE-2017-3167 CVE-2017-3169 CVE-2017-7668 CVE-2017-7679

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here