Information disclosure in Apache HTTP Server - CVE-2017-9788

 

Information disclosure in Apache HTTP Server - CVE-2017-9788

Published: July 13, 2017 / Updated: July 14, 2017


Vulnerability identifier: #VU7517
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-9788
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote unauthenticated attacker to obtain potentially sensitive information on the targeted system.

The weakness exists due to improper initialization of the value placeholder in [Proxy-]Authorization headers of type 'Digest' before or between successive key=value assignments by mod_auth_digest. A remote attacker can provide an initial key with no '=' assignment to cause the stale value of uninitialized pool memory used by the prior request to leak.

Successful exploitation of the vulnerability results in information disclosure.


Affected software

Apache HTTP Server
JBoss Enterprise Web Server
Arch Linux
Debian Linux
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Ubuntu
Slackware Linux
Tenable.sc
Dell Secure Connect Gateway
IBM Cloud Pak for Business Automation
JBoss Enterprise Application Platform
httpd (Red Hat package)

How to mitigate CVE-2017-9788

Update Apache HTTP server to version 2.2.34 or 2.4.26.

Tenable.sc - update to 5.13.0
Dell Secure Connect Gateway - update to 5.12.00.10
httpd (Red Hat package) - update to 2.4.6-40.el7_2.6
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF037, 24.0.0-IF003

External References

Related Security Bulletins