NULL pointer dereference in Apache HTTP Server - CVE-2017-3169
Published: June 20, 2017 / Updated: April 7, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform denial of service attack.
The vulnerability exists due to a NULL pointer dereference error within mod_ssl module, when third-party modules call ap_hook_process_connection() function during an HTTP request to an HTTPS port. A remote attacker can send a specially crafted HTTP request and crash the affected web server.
Affected software
Arch Linux
Amazon Linux AMI
Gentoo Linux
Debian Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Ubuntu
Slackware Linux
Fedora
JBoss Core Services
Tenable.sc
apache2 (Alpine package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
httpd (Red Hat package)
httpd
firefox (Red Hat package)
Dell Secure Connect Gateway
IBM Cloud Pak for Business Automation
XtremIO XMS
How to mitigate CVE-2017-3169
apache2 (Alpine package) - update to 2.4.26-r0
Dell Secure Connect Gateway - update to 5.12.00.10
httpd (Red Hat package) - update to 2.4.6-40.el7_2.6
httpd - addressed in versions 2.4.26-1.fc24, 2.4.26-1.fc25, 2.4.26-1.fc26, 2.4.27-1.fc25, 2.4.27-2.fc25
XtremIO XMS - update to 6.3.1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF037, 24.0.0-IF003
firefox (Red Hat package) - update to 115.13.0-3.el8_4
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache HTTP server
- Ubuntu update for Apache HTTP Server
- Arch Linux update for apache
- Slackware Linux update for httpd
- Red Hat update for Apache HTTP server
- Red Hat update for Apache HTTP server
- Red Hat update for Apache HTTP server
- Ubuntu update for Apache HTTP Server
- Debian update for apache2
- Gentoo update for Apache
- Amazon Linux AMI update for httpd
- Amazon Linux AMI update for httpd24
- Red Hat update for Apache
- Red Hat update for Apache
- Red Hat update for Apache
- Red Hat update for httpd
- Red Hat update for httpd
- Multiple vulnerabilities in Tenable.sc
- NULL pointer dereference in apache2 (Alpine package)
- Multiple vulnerabilities in DELL Secure Connect Gateway Security
- Multiple vulnerabilities in Dell EMC XtremIO
- Red Hat Enterprise Linux 8 update for firefox
- Fedora 25 update for httpd
- Fedora 26 update for httpd
- Fedora 24 update for httpd
- Fedora 25 update for httpd
- Fedora 25 update for httpd
- Red Hat Enterprise Linux 7 update for httpd
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation