Race condition in Apache HTTP Server - CVE-2019-0217

 

Race condition in Apache HTTP Server - CVE-2019-0217

Published: April 2, 2019


Vulnerability identifier: #VU18111
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2019-0217
CWE-ID: CWE-362
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to impersonate other users.

The vulnerability exists due to a race condition within the mod_auth_digests module. A remote authenticated attacker can send a series of requests and impersonate other users under a threaded MPM.

Affected software

Apache HTTP Server
JBoss Core Services
Red Hat Software Collections
apache2 (Debian package)
apache2 (Alpine package)
apache2 (Ubuntu package)
httpd
Dell Secure Connect Gateway
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
Data Computing Appliance (DCA)
Maximo Application Suite - IoT Component
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)

How to mitigate CVE-2019-0217

Install updates from vendor's website.

Apache HTTP Server - update to 2.4.39
apache2 (Debian package) - update to 2.4.25-3+deb9u7
apache2 (Alpine package) - update to 2.4.39-r0
apache2 (Ubuntu package) - addressed in versions 2.4.7-1ubuntu4.22, 2.4.18-2ubuntu3.10, 2.4.29-1ubuntu4.6, 2.4.34-1ubuntu2.1
Dell Secure Connect Gateway - update to 5.12.00.10
httpd - addressed in versions 2.4.39-1.1.fc28, 2.4.39-2.fc29, 2.4.39-2.fc30
Data Computing Appliance (DCA) - update to 4.3.0.0
Dell EMC Unity Operating Environment (OE) - update to 5.0.0.0.5.116
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.0.0.5.116
Maximo Application Suite - IoT Component - addressed in versions 8.7.20, 8.8.16, 9.0.6

External References

Related Security Bulletins