CVE-2017-15710

Advisory lineage Upstream: 0 Downstream: 16
Modified
Published: 26 Mar 2018, 15:00
Last modified:17 Sept 2024, 03:37

Vulnerability Summary

Overall Risk (default)
medium
33/100
CVSS Score
7.5 HIGH
v3.0 (nvd)
EPSS Score
13.19% MEDIUM
13% probability +5.97%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

26 Mar 2018, 15:00
Published
Vulnerability first disclosed
17 Sept 2024, 03:37
Last Modified
Vulnerability information updated

Description

In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-Language header value to lookup the right charset encoding when verifying the user's credentials. If the header value is not present in the charset conversion table, a fallback mechanism is used to truncate it to a two characters value to allow a quick retry (for example, 'en-US' is truncated to 'en'). A header value of less than two characters forces an out of bound write of one NUL byte to a memory location that is not part of the string. In the worst case, quite unlikely, the process would crash which could be used as a Denial of Service attack. In the more likely case, this memory is already reserved for future use and the issue has no effect at all.

CVSS Metrics

  • v3.0HIGHScore: 7.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 13.19% Percentile: 94%

Techniques & Countermeasures

  • CWE-787Out-of-bounds Write

    The product writes data past the end, or before the beginning, of the intended buffer.

Affected Systems

  • apache software foundationapache http server

    2.0.23 to 2.0.65 | 2.2.0 to 2.2.34 | 2.4.0 to 2.4.29

  • UnknownHTTP Server

    2.4.1 | 2.4.2 | 2.4.3 | 2.4.4 | 2.4.6 | 2.4.7 | 2.4.9 | 2.4.10 | 2.4.12 | 2.4.16 | 2.4.17 | 2.4.18 | 2.4.20 | 2.4.23 | 2.4.25 | 2.4.26 | 2.4.27 | 2.4.28 | 2.4.29

  • canonicalubuntu_linux

    12.04 | 14.04 | 16.04 | 17.10 | 18.04

  • debiandebian_linux

    7.0 | 8.0 | 9.0

  • netappclustered_data_ontap

    na

  • netappsantricity_cloud_connector

    na

  • netappstorage_automation_store

    na

  • netappstoragegrid

    na

  • redhatenterprise_linux

    6.0 | 7.0 | 7.4 | 7.5 | 7.6

References (27)