CVE Database
/

CVE-2017-9798

Back to search

CVE-2017-9798

Published: Sep 18, 2017

Modified: Nov 4, 2025

PUBLISHED

Description

Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user's .htaccess file, or if httpd.conf has certain misconfigurations, aka Optionsbleed. This affects the Apache HTTP Server through 2.2.34 and 2.4.x through 2.4.27. The attacker sends an unauthenticated OPTIONS HTTP request when attempting to read secret data. This is a use-after-free issue and thus secret data is not always sent, and the specific data depends on many factors including configuration. Exploitation with .htaccess can be blocked with a patch to the ap_limit_section function in server/core.c.

VendorProductVersions

Apache Software Foundation

Apache HTTP Server

affected
Apache HTTP Server through 2.2.34 and 2.4.x through 2.4.27

References

RHSA-2017:3113
vendor-advisory
x_refsource_REDHAT
100872
vdb-entry
x_refsource_BID
RHSA-2017:2882
vendor-advisory
x_refsource_REDHAT
RHSA-2017:2972
vendor-advisory
x_refsource_REDHAT
1039387
vdb-entry
x_refsource_SECTRACK
RHSA-2017:3475
vendor-advisory
x_refsource_REDHAT
RHSA-2017:3240
vendor-advisory
x_refsource_REDHAT
RHSA-2017:3195
vendor-advisory
x_refsource_REDHAT
RHSA-2017:3018
vendor-advisory
x_refsource_REDHAT
RHSA-2017:3239
vendor-advisory
x_refsource_REDHAT
RHSA-2017:3476
vendor-advisory
x_refsource_REDHAT
105598
vdb-entry
x_refsource_BID
RHSA-2017:3114
vendor-advisory
x_refsource_REDHAT
RHSA-2017:3477
vendor-advisory
x_refsource_REDHAT
RHSA-2017:3194
vendor-advisory
x_refsource_REDHAT
RHSA-2017:3193
vendor-advisory
x_refsource_REDHAT
DSA-3980
vendor-advisory
x_refsource_DEBIAN
42745
exploit
x_refsource_EXPLOIT-DB
GLSA-201710-32
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now