CVE-2016-8743

Severity
7.5HIGH
EPSS
8.4%
top 7.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 27
Latest updateMay 13

Description

Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and sent in response lines and headers. Accepting these different behaviors represented a security concern when httpd participates in any chain of proxies or interacts with back-end application servers, either through mod_proxy or using conventional CGI mechanisms, and may result in request smuggling, response splitting and cache pollution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages7 packages

NVDapache/http_server2.2.02.2.31+1
CVEListV5apache_software_foundation/apache_http_server2.2.0 to 2.2.31, 2.4.1 to 2.4.23
Debianapache2< 2.4.25-1+3

Also affects: Debian Linux 8.0, 9.0, Enterprise Linux 7.3, 7.4, 7.5, 7.6, 7.7

Patches

🔴Vulnerability Details

3
GHSA
GHSA-2rfh-2gh8-v9fq: Apache HTTP Server, in all releases prior to 22022-05-13
OSV
CVE-2016-8743: Apache HTTP Server, in all releases prior to 22017-07-27
CVEList
CVE-2016-8743: Apache HTTP Server, in all releases prior to 22017-07-27

📋Vendor Advisories

7
Apple
CVE-2016-8743: macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan2017-10-31
Apple
CVE-2016-8743: macOS High Sierra 10.132017-09-25
Ubuntu
Apache HTTP Server vulnerabilities2017-07-31
Ubuntu
Apache HTTP Server vulnerabilities2017-05-09
Apple
CVE-2016-8743: macOS Sierra 10.12.4, Security Update 2017-001 El Capitan, and Security Update 2017-001 Yosemite2017-03-27

💬Community

2
Bugzilla
CVE-2016-0736 CVE-2016-2161 CVE-2016-8743 httpd: various flaws [fedora-all]2016-12-21
Bugzilla
CVE-2016-8743 httpd: Apache HTTP Request Parsing Whitespace Defects2016-12-21
CVE-2016-8743 (HIGH CVSS 7.5) | Apache HTTP Server | cvebase.io