[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2017-892 ---- httpd

ID: oval:org.secpod.oval:def:1600771Date: (C)2017-09-21   (M)2024-02-19
Class: PATCHFamily: unix




A NULL pointer dereference flaw was found in the httpd's mod_ssl module. A remote attacker could use this flaw to cause an httpd child process to crash if another module used by httpd called a certain API function during the processing of an HTTPS request. It was discovered that the use of httpd's ap_get_basic_auth_pw API function outside of the authentication phase could lead to authentication bypass. A remote attacker could possibly use this flaw to bypass required authentication if the API was used incorrectly by one of the modules used by httpd. A buffer over-read flaw was found in the httpd's mod_mime module. A user permitted to modify httpd's MIME configuration could use this flaw to cause httpd child process to crash. It was discovered that the httpd's mod_auth_digest module did not properly initialize memory before using it when processing certain headers related to digest authentication. A remote attacker could possibly use this flaw to disclose potentially sensitive information or cause httpd child process to crash by sending specially crafted requests to a server

Platform:
Amazon Linux AMI
Product:
httpd
Reference:
ALAS-2017-892
CVE-2017-3169
CVE-2017-3167
CVE-2017-7679
CVE-2017-9788
CVE    4
CVE-2017-3167
CVE-2017-3169
CVE-2017-9788
CVE-2017-7679
...
CPE    33
cpe:/o:amazon:linux
cpe:/a:apache:http_server:2.2.26
cpe:/a:apache:http_server:2.2.27
cpe:/a:apache:http_server:2.2.24
...

© SecPod Technologies