cbcvebase.
CVE-2017-7659
published 2017-07-26

CVE-2017-7659: A maliciously constructed HTTP/2 request could cause mod_http2 in Apache HTTP Server 2.4.24, 2.4.25 to dereference a NULL pointer and crash the server process.

PriorityP275high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
53.94%
98.9th percentile
A maliciously constructed HTTP/2 request could cause mod_http2 in Apache HTTP Server 2.4.24, 2.4.25 to dereference a NULL pointer and crash the server process.

Affected

5 ranges
VendorProductVersion rangeFixed in
apachehttp_server
apachehttp_server
apache_software_foundationapache_http_server
applemacos_high_sierra_10.13.1_security_update_2017-001_sierra_and_security_update_20
debianapache2< apache2 2.4.25-4 (bookworm)apache2 2.4.25-4 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

  • Target mod_http2 module in Apache HTTP Server versions 2.4.24 and 2.4.25 — a specially crafted HTTP/2 request triggers a NULL pointer dereference and crashes the httpd child process
  • Monitor for unexpected httpd child process crashes, particularly following HTTP/2 requests — the crash vector is a remote attacker sending a specially crafted HTTP/2 request to the mod_http2 module
  • Review upstream patch commits for mod_http2 NULL pointer dereference fix to understand the exact code path triggered — trunk fix at commit 672187c168b94b562d8065e08e2cad5b00cdd0e3, backported to 2.4 branch at bc6ad1ef31f2c9e8f5eb453293a4b9caceaa191d
  • ·Vulnerability only affects Apache HTTP Server versions 2.4.24 and 2.4.25 with mod_http2 enabled; all Red Hat Enterprise Linux 5/6/7 and JBoss packages are listed as Not Affected, suggesting mod_http2 was not shipped or enabled in those builds
  • ·The vulnerability requires HTTP/2 to be active (mod_http2 loaded and H2/H2C enabled in configuration); deployments without HTTP/2 support enabled are not exploitable

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vulncheck7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.