CVE-2017-9788

Advisory lineage Upstream: 0 Downstream: 21
Modified
Published: 13 Jul 2017, 16:00
Last modified:16 Sept 2024, 17:53

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.1 CRITICAL
v3.0 (nvd)
EPSS Score
49.5% HIGH
49% probability -3.72%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

13 Jul 2017, 16:00
Published
Vulnerability first disclosed
16 Sept 2024, 17:53
Last Modified
Vulnerability information updated

Description

In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assignments by mod_auth_digest. Providing an initial key with no '=' assignment could reflect the stale value of uninitialized pool memory used by the prior request, leading to leakage of potentially confidential information, and a segfault in other cases resulting in denial of service.

CVSS Metrics

  • v3.0CRITICALScore: 9.1CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
  • v2.0MEDIUMScore: 6.4AV:N/AC:L/Au:N/C:P/I:N/A:P

EPSS Trends

Current EPSS score: 49.50% Percentile: 98%

Techniques & Countermeasures

  • CWE-20Improper Input Validation

    The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Affected Systems

  • apache software foundationapache http server

    2.2.0 to 2.2.33 | 2.4.1 to 2.4.26

  • UnknownHTTP Server

    ≤ 2.2.33 | ≥ 2.4.0, ≤ 2.4.26

  • applemac_os_x

    < 10.13.1

  • debiandebian_linux

    8.0 | 9.0

  • netapponcommand_unified_manager

    na

  • netappstorage_automation_store

    na

  • oraclesecure_global_desktop

    5.3

  • redhatenterprise_linux_desktop

    6.0 | 7.0

  • redhatenterprise_linux_server

    6.0 | 7.0

  • redhatenterprise_linux_server_aus

    7.2 | 7.3 | 7.4 | 7.6

  • redhatenterprise_linux_server_eus

    6.7 | 7.2 | 7.3 | 7.4 | 7.5 | 7.6

  • redhatenterprise_linux_server_tus

    7.2 | 7.3 | 7.4 | 7.6

  • redhatenterprise_linux_workstation

    6.0 | 7.0

  • redhatjboss_core_services

    1.0

  • redhatjboss_enterprise_application_platform

    6.0.0 | 6.4.0

  • redhatjboss_enterprise_web_server

    2.0.0

References (46)