CVE-2017-3169

Advisory lineage Upstream: 0 Downstream: 19
Modified
Published: 20 Jun 2017, 01:00
Last modified:05 Aug 2024, 14:16

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.0 (nvd)
EPSS Score
30.77% HIGH
31% probability -2.33%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

20 Jun 2017, 01:00
Published
Vulnerability first disclosed
05 Aug 2024, 14:16
Last Modified
Vulnerability information updated

Description

In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer when third-party modules call ap_hook_process_connection() during an HTTP request to an HTTPS port.

CVSS Metrics

  • v3.0CRITICALScore: 9.8CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 30.77% Percentile: 97%

Techniques & Countermeasures

  • CWE-476NULL Pointer Dereference

    The product dereferences a pointer that it expects to be valid but is NULL.

Affected Systems

  • apache software foundationapache http server

    2.2.0 to 2.2.32 | 2.4.0 to 2.4.25

  • UnknownHTTP Server

    2.2.0 | 2.2.2 | 2.2.3 | 2.2.11 | 2.2.12 | 2.2.13 | 2.2.14 | 2.2.15 | 2.2.16 | 2.2.17 | 2.2.18 | 2.2.19 | 2.2.20 | 2.2.21 | 2.2.22 | 2.2.23 | 2.2.24 | 2.2.25 | 2.2.26 | 2.2.27 | 2.2.29 | 2.2.30 | 2.2.31 | 2.2.32 | 2.4.1 | 2.4.2 | 2.4.10 | 2.4.12 | 2.4.16 | 2.4.17 | 2.4.18 | 2.4.20 | 2.4.23 | 2.4.25

References (42)