Race condition in Apache HTTP Server - CVE-2019-0217
Published: April 2, 2019
Vulnerability identifier: #VU18111
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2019-0217
CWE-ID: CWE-362
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated user to impersonate other users.
The vulnerability exists due to a race condition within the mod_auth_digests module. A remote authenticated attacker can send a series of requests and impersonate other users under a threaded MPM.
Affected software
Apache HTTP Server
JBoss Core Services
Red Hat Software Collections
apache2 (Debian package)
apache2 (Alpine package)
apache2 (Ubuntu package)
httpd
Dell Secure Connect Gateway
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
Data Computing Appliance (DCA)
Maximo Application Suite - IoT Component
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
JBoss Core Services
Red Hat Software Collections
apache2 (Debian package)
apache2 (Alpine package)
apache2 (Ubuntu package)
httpd
Dell Secure Connect Gateway
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
Data Computing Appliance (DCA)
Maximo Application Suite - IoT Component
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
How to mitigate CVE-2019-0217
Install updates from vendor's website.
Apache HTTP Server - update to 2.4.39
apache2 (Debian package) - update to 2.4.25-3+deb9u7
apache2 (Alpine package) - update to 2.4.39-r0
apache2 (Ubuntu package) - addressed in versions 2.4.7-1ubuntu4.22, 2.4.18-2ubuntu3.10, 2.4.29-1ubuntu4.6, 2.4.34-1ubuntu2.1
Dell Secure Connect Gateway - update to 5.12.00.10
httpd - addressed in versions 2.4.39-1.1.fc28, 2.4.39-2.fc29, 2.4.39-2.fc30
Data Computing Appliance (DCA) - update to 4.3.0.0
Dell EMC Unity Operating Environment (OE) - update to 5.0.0.0.5.116
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.0.0.5.116
Maximo Application Suite - IoT Component - addressed in versions 8.7.20, 8.8.16, 9.0.6
apache2 (Debian package) - update to 2.4.25-3+deb9u7
apache2 (Alpine package) - update to 2.4.39-r0
apache2 (Ubuntu package) - addressed in versions 2.4.7-1ubuntu4.22, 2.4.18-2ubuntu3.10, 2.4.29-1ubuntu4.6, 2.4.34-1ubuntu2.1
Dell Secure Connect Gateway - update to 5.12.00.10
httpd - addressed in versions 2.4.39-1.1.fc28, 2.4.39-2.fc29, 2.4.39-2.fc30
Data Computing Appliance (DCA) - update to 4.3.0.0
Dell EMC Unity Operating Environment (OE) - update to 5.0.0.0.5.116
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.0.0.5.116
Maximo Application Suite - IoT Component - addressed in versions 8.7.20, 8.8.16, 9.0.6
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache HTTP Server
- Debian update for apache2
- Ubuntu update for Apache HTTP Server
- OpenSUSE Linux update for apache2
- OpenSUSE Linux update for apache2
- OpenSUSE Linux update for apache2
- Red Hat update for httpd
- Red Hat update for httpd:2.4
- Red Hat JBoss Core Services update for Apache HTTP Server 2.4.37
- Red Hat JBoss Core Services update for Apache HTTP Server 2.4.37 (RHEL 6)
- Red Hat JBoss Core Services update Apache HTTP Server 2.4.37 (RHEL 7)
- Red Hat Software Collections update for httpd24-httpd
- Race condition in apache2 (Alpine package)
- Multiple vulnerabilities in DELL Secure Connect Gateway Security
- Multiple vulnerabilities in Dell EMC Unity Family
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- Multiple vulnerabilities in IBM Maximo Application Suite - IoT Component
- Fedora 29 update for httpd
- Fedora 28 update for httpd
- Fedora 30 update for httpd