Wind River Support Network

HomeDefectsLIN6-13810
Fixed

LIN6-13810 : Security Advisory - apache2 - CVE-2017-9798

Created: Sep 26, 2017    Updated: Dec 3, 2018
Resolved Date: Nov 27, 2017
Found In Version: 6.0.0.34
Fix Version: 6.0.0.36
Severity: Standard
Applicable for: Wind River Linux 6
Component/s: Userspace

Description

Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user's .htaccess file, or if httpd.conf has certain misconfigurations, aka Optionsbleed. This affects the Apache HTTP Server through 2.2.34 and 2.4.x through 2.4.27. The attacker sends an unauthenticated OPTIONS HTTP request when attempting to read secret data. This is a use-after-free issue and thus secret data is not always sent, and the specific data depends on many factors including configuration. Exploitation with .htaccess can be blocked with a patch to the ap_limit_section function in server/core.c.

https://nvd.nist.gov/vuln/detail/CVE-2017-9798

Other Downloads


Live chat
Online