Use-after-free error in Apache HTTP Server - CVE-2017-9789

 

Use-after-free error in Apache HTTP Server - CVE-2017-9789

Published: July 14, 2017 / Updated: July 14, 2017


Vulnerability identifier: #VU7518
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-9789
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote unauthenticated attacker to cause DoS condition on the targeted system.

The weakness exists due to use-after-free condition in the mod_http2 function. A remote attacker can trigger memory corruption and cause the server to crash.

Successful exploitation of the vulnerability results in denial of service.


Affected software

Apache HTTP Server
Arch Linux
Gentoo Linux
Slackware Linux
apache2 (Alpine package)
Dell Secure Connect Gateway

How to mitigate CVE-2017-9789

Update to version 2.4.27.

apache2 (Alpine package) - update to 2.4.27-r0
Dell Secure Connect Gateway - update to 5.12.00.10

External References

Related Security Bulletins