cbcvebase.
CVE-2017-7679
published 2017-06-20

CVE-2017-7679: In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious Content-Type response…

critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious Content-Type response header.

Affected

7 ranges
VendorProductVersion rangeFixed in
apachehttp_server>= 2.2.0 < 2.2.332.2.33
apachehttp_server>= 2.4.0 < 2.4.262.4.26
apachehttpd
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
applemacos_high_sierra_10.13.1_security_update_2017-001_sierra_and_security_update_20
debianapache2< apache2 2.4.25-4 (bookworm)apache2 2.4.25-4 (bookworm)

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL