cbcvebase.
CVE-2017-7668
published 2017-06-20

CVE-2017-7668: The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence of request headers, an attacker may be able to cause a segmentation fault, or to force ap_find_token() to return an incorrect value.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
apachehttp_server
apachehttp_server
apachehttp_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
applemac_os_x< 10.13.110.13.1
applemac_os_x
applemac_os_x
applemac_os_x>= 10.11.0 < 10.11.610.11.6
applemac_os_x>= 10.12.0 < 10.12.610.12.6
applemacos_high_sierra_10.13.1_security_update_2017-001_sierra_and_security_update_20
debianapache2< apache2 2.4.25-4 (bookworm)apache2 2.4.25-4 (bookworm)
debiandebian_linux
debiandebian_linux
oraclesecure_global_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv9.8CRITICAL
vulncheck7.5HIGH