#VU7116 NULL pointer dereference in Apache HTTP Server - CVE-2017-3169
Published: June 20, 2017 / Updated: April 7, 2020
Apache HTTP Server
Apache Foundation
Description
The vulnerability allows a remote attacker to perform denial of service attack.
The vulnerability exists due to a NULL pointer dereference error within mod_ssl module, when third-party modules call ap_hook_process_connection() function during an HTTP request to an HTTPS port. A remote attacker can send a specially crafted HTTP request and crash the affected web server.