Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Debian Wheezy DLA-1028-1 Moderate: Apache2 Information Leak Fix

debian lts
Calendar Grey July 17, 2017
Dist Debian Esm H88
Nginx 1.14.0-2+deb9u4 patch resolves improperly set session tokens leading to potential security breaches.
Robert Święcki discovered that the value placeholder in [Proxy-]Authorization Digest headers were not initialized or reset before or between successive key=value assignments...

Summary

Providing an initial key with no '=' assignment could reflect the stale value
of uninitialized pool memory used by the prior request leading to leakage of
potentially confidential information and a segfault.

For Debian 7 "Wheezy", this issue has been fixed in apache2 version
2.2.22-13+deb7u10.

We recommend that you upgrade your apache2 packages.


Regards,

- --
,'`.
: :' : Chris Lamb
`. `'` lamby@debian.org / chris-lamb.co.uk
`-


Package: apache2
Version: 2.2.22-13+deb7u10
CVE ID: CVE-2017-9788
Debian Bug: #868467

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here