Information disclosure in Apache HTTP Server - CVE-2017-9788
Published: July 13, 2017 / Updated: July 14, 2017
Vulnerability details
The weakness exists due to improper initialization of the value placeholder in [Proxy-]Authorization headers of type 'Digest' before or between successive key=value assignments by mod_auth_digest. A remote attacker can provide an initial key with no '=' assignment to cause the stale value of uninitialized pool memory used by the prior request to leak.
Successful exploitation of the vulnerability results in information disclosure.
Affected software
JBoss Enterprise Web Server
Arch Linux
Debian Linux
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Ubuntu
Slackware Linux
Tenable.sc
Dell Secure Connect Gateway
IBM Cloud Pak for Business Automation
JBoss Enterprise Application Platform
httpd (Red Hat package)
How to mitigate CVE-2017-9788
Dell Secure Connect Gateway - update to 5.12.00.10
httpd (Red Hat package) - update to 2.4.6-40.el7_2.6
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF037, 24.0.0-IF003
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache HTTP server
- Two vulnerabilities in Apache HTTP Server
- Slackware Linux update for httpd
- Arch Linux update for apache
- Debian update for apache2
- Ubuntu update for Apache HTTP Server
- Red Hat update for Apache HTTP server
- Red Hat update for Apache HTTP server
- Red Hat update for Apache HTTP server
- Ubuntu update for Apache HTTP Server
- Gentoo update for Apache
- Amazon Linux AMI update for httpd
- Red Hat update for Red Hat JBoss Enterprise Application Platform 6.4.18
- Red Hat update for httpd
- Red Hat update for httpd
- Red Hat update for Red Hat JBoss Web Server
- Multiple vulnerabilities in Tenable.sc
- Multiple vulnerabilities in DELL Secure Connect Gateway Security
- Red Hat Enterprise Linux 7 update for httpd
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation