CVE Database
/

CVE-2017-9788

Back to search

CVE-2017-9788

Published: Jul 13, 2017

Modified: Sep 16, 2024

PUBLISHED

Description

In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assignments by mod_auth_digest. Providing an initial key with no '=' assignment could reflect the stale value of uninitialized pool memory used by the prior request, leading to leakage of potentially confidential information, and a segfault in other cases resulting in denial of service.

VendorProductVersions

Apache Software Foundation

Apache HTTP Server

affected
2.2.0 to 2.2.33
affected
2.4.1 to 2.4.26

References

RHSA-2017:3113
vendor-advisory
x_refsource_REDHAT
RHSA-2017:2479
vendor-advisory
x_refsource_REDHAT
RHSA-2017:2483
vendor-advisory
x_refsource_REDHAT
RHSA-2017:3240
vendor-advisory
x_refsource_REDHAT
RHSA-2017:2709
vendor-advisory
x_refsource_REDHAT
RHSA-2017:3195
vendor-advisory
x_refsource_REDHAT
99569
vdb-entry
x_refsource_BID
RHSA-2017:3239
vendor-advisory
x_refsource_REDHAT
RHSA-2017:3114
vendor-advisory
x_refsource_REDHAT
RHSA-2017:3194
vendor-advisory
x_refsource_REDHAT
1038906
vdb-entry
x_refsource_SECTRACK
RHSA-2017:3193
vendor-advisory
x_refsource_REDHAT
RHSA-2017:2710
vendor-advisory
x_refsource_REDHAT
DSA-3913
vendor-advisory
x_refsource_DEBIAN
RHSA-2017:2708
vendor-advisory
x_refsource_REDHAT
GLSA-201710-32
vendor-advisory
x_refsource_GENTOO
RHSA-2017:2478
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now