Out-of-bound read in Apache HTTP Server - CVE-2017-7668
Published: June 20, 2017 / Updated: July 14, 2017
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to boundary error when processing token lists within ap_find_token() function. A remote unauthenticated attacker can create a specially crafted sequence of HTTP headers and refer to data past the end of the search string.
Successful exploitation of this vulnerability results segmentation fault and web server crash.
Affected software
Arch Linux
Amazon Linux AMI
Gentoo Linux
Debian Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Ubuntu
Slackware Linux
Fedora
Tenable.sc
apache2 (Alpine package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
httpd (Red Hat package)
httpd
firefox (Red Hat package)
How to mitigate CVE-2017-7668
apache2 (Alpine package) - update to 2.4.26-r0
httpd (Red Hat package) - update to 2.4.6-40.el7_2.6
httpd - addressed in versions 2.4.26-1.fc24, 2.4.26-1.fc25, 2.4.26-1.fc26, 2.4.27-1.fc25, 2.4.27-2.fc25
firefox (Red Hat package) - update to 115.13.0-3.el8_4
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache HTTP server
- Ubuntu update for Apache HTTP Server
- Arch Linux update for apache
- Slackware Linux update for httpd
- Red Hat update for Apache HTTP server
- Red Hat update for Apache HTTP server
- Ubuntu update for Apache HTTP Server
- Debian update for apache2
- Gentoo update for Apache
- Amazon Linux AMI update for httpd24
- Red Hat update for httpd
- Multiple vulnerabilities in Tenable.sc
- Out-of-bound read in apache2 (Alpine package)
- Red Hat Enterprise Linux 8 update for firefox
- Fedora 25 update for httpd
- Fedora 26 update for httpd
- Fedora 24 update for httpd
- Fedora 25 update for httpd
- Fedora 25 update for httpd
- Red Hat Enterprise Linux 7 update for httpd