Tracker / CVE-2017-7668
CVE-2017-7668
High 7.5
The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence of request headers, an attacker may be able to cause a segmentation fault, or to force ap_find_token() to return an incorrect value.
Affected products and versions
| apache | http_server |
|---|---|
| apple | mac_os_x |
| apple | mac_os_x · … → 10.13.1 |
| apple | mac_os_x · 10.11.0 → 10.11.6 |
| apple | mac_os_x · 10.12.0 → 10.12.6 |
| debian | debian_linux |
| netapp | clustered_data_ontap |
| netapp | oncommand_unified_manager |
| netapp | storagegrid |
| oracle | secure_global_desktop |
| redhat | enterprise_linux_desktop |
| redhat | enterprise_linux_eus |
| redhat | enterprise_linux_server |
| redhat | enterprise_linux_server_aus |
| redhat | enterprise_linux_server_tus |
| redhat | enterprise_linux_workstation |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.