CESA-2017:2478 -- centos 6 httpdID: oval:org.secpod.oval:def:204546 | Date: (C)2017-08-18 (M)2024-02-19 |
Class: PATCH | Family: unix |
The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server. Security Fix: * It was discovered that the httpd"s mod_auth_digest module did not properly initialize memory before using it when processing certain headers related to digest authentication. A remote attacker could possibly use this flaw to disclose potentially sensitive information or cause httpd child process to crash by sending specially crafted requests to a server. * It was discovered that the use of httpd"s ap_get_basic_auth_pw API function outside of the authentication phase could lead to authentication bypass. A remote attacker could possibly use this flaw to bypass required authentication if the API was used incorrectly by one of the modules used by httpd. * A NULL pointer dereference flaw was found in the httpd"s mod_ssl module. A remote attacker could use this flaw to cause an httpd child process to crash if another module used by httpd called a certain API function during the processing of an HTTPS request. * A buffer over-read flaw was found in the httpd"s mod_mime module. A user permitted to modify httpd"s MIME configuration could use this flaw to cause httpd child process to crash