Severity
9.1CRITICAL
EPSS
52.6%
top 2.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 13
Latest updateMay 13

Description

In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assignments by mod_auth_digest. Providing an initial key with no '=' assignment could reflect the stale value of uninitialized pool memory used by the prior request, leading to leakage of potentially confidential information, and a segfault in other cases resulting in denial of service.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HExploitability: 3.9 | Impact: 5.2

Affected Packages11 packages

Debianapache2< 2.4.27-1+3
NVDapache/http_server2.4.02.4.26+1
CVEListV5apache_software_foundation/apache_http_server2.2.0 to 2.2.33, 2.4.1 to 2.4.26+1
NVDapple/mac_os_x< 10.13.1

Also affects: Debian Linux 8.0, 9.0, Enterprise Linux 7.2, 7.3, 7.4, 7.6, 6.7, 7.5

Patches

🔴Vulnerability Details

4
GHSA
GHSA-w97h-p5ff-7q69: In Apache httpd before 22022-05-13
OSV
CVE-2017-9788: In Apache httpd before 22017-07-13
CVEList
CVE-2017-9788: In Apache httpd before 22017-07-13
VulnCheck
Apache HTTP Server Improper Input Validation2017

📋Vendor Advisories

5
Apple
CVE-2017-9788: macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan2017-10-31
Ubuntu
Apache HTTP Server vulnerability2017-08-01
Ubuntu
Apache HTTP Server vulnerability2017-07-27
Red Hat
httpd: Uninitialized memory reflection in mod_auth_digest2017-07-11
Debian
CVE-2017-9788: apache2 - In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in ...2017

💬Community

2
Bugzilla
CVE-2017-9788 httpd: Uninitialized memory reflection in mod_auth_digest2017-07-13
Bugzilla
CVE-2017-9788 CVE-2017-9789 httpd: various flaws [fedora-all]2017-07-13