Out-of-bound read in Apache HTTP Server - CVE-2017-7668

 

Out-of-bound read in Apache HTTP Server - CVE-2017-7668

Published: June 20, 2017 / Updated: July 14, 2017


Vulnerability identifier: #VU7117
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-7668
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to boundary error when processing token lists within ap_find_token() function. A remote unauthenticated attacker can create a specially crafted sequence of HTTP headers and refer to data past the end of the search string. 

Successful exploitation of this vulnerability results segmentation fault and web server crash.


Affected software

Apache HTTP Server
Arch Linux
Amazon Linux AMI
Gentoo Linux
Debian Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Ubuntu
Slackware Linux
Fedora
Tenable.sc
apache2 (Alpine package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
httpd (Red Hat package)
httpd
firefox (Red Hat package)

How to mitigate CVE-2017-7668

Update to version 2.2.34 or 2.4.26.

Tenable.sc - update to 5.13.0
apache2 (Alpine package) - update to 2.4.26-r0
httpd (Red Hat package) - update to 2.4.6-40.el7_2.6
httpd - addressed in versions 2.4.26-1.fc24, 2.4.26-1.fc25, 2.4.26-1.fc26, 2.4.27-1.fc25, 2.4.27-2.fc25
firefox (Red Hat package) - update to 115.13.0-3.el8_4

External References

Related Security Bulletins