CVE-2017-9788
Providing an initial key with no '=' assignment could reflect the stale value of uninitialized pool memory used by the prior request, leading to leakage of potentially confidential information, and a segfault in other cases resulting in denial of service.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 56.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assignments by mod_auth_digest. Providing an initial key with no '=' assignment could reflect the stale value of uninitialized pool memory used by the prior request, leading to leakage of potentially confidential information, and a segfault in other cases resulting in denial of service.
- CVSS 3.0
- 9.1 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
- EPSS
- 56.77% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20, CWE-200
- Affected
- apache/http server · debian/debian linux · apple/mac os x · netapp/oncommand unified manager · netapp/storage automation store · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server eus · redhat/enterprise linux server tus · redhat/enterprise linux workstation · redhat/jboss core services · redhat/jboss enterprise application platform · redhat/jboss enterprise web server · oracle/secure global desktop
- Source
- security@apache.org
References
- http://www.debian.org/security/2017/dsa-3913Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/99569Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038906Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:2478Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2479Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2483Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2708Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2709Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2710Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3113Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3114Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3193Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3194Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3195Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3239Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3240Third Party Advisory
- https://httpd.apache.org/security/vulnerabilities_22.htmlVendor Advisory
- https://httpd.apache.org/security/vulnerabilities_24.htmlVendor Advisory
- https://lists.apache.org/thread.html/0dd69204a6bd643cc4e9ccd008f07a9375525d977c6ebeb07a881afb%40%3Cannounce.httpd.apache.org%3E
- https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r15f9aa4427581a1aecb4063f1b4b983511ae1c9935e2a0a6876dad3c%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r6521a7f62276340eabdb3339b2aa9a38c5f59d978497a1f794af53be%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r8c9983f1172a3415f915ddb7e14de632d2d0c326eb1285755a024165%40%3Ccvs.httpd.apache.org%3E
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.