Oval Definition:oval:com.redhat.rhsa:def:20172479
Revision Date:2017-08-15Version:637
Title:RHSA-2017:2479: httpd security update (Important)
Description:The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.

Security Fix(es):

  • It was discovered that the httpd's mod_auth_digest module did not properly initialize memory before using it when processing certain headers related to digest authentication. A remote attacker could possibly use this flaw to disclose potentially sensitive information or cause httpd child process to crash by sending specially crafted requests to a server. (CVE-2017-9788)

  • It was discovered that the use of httpd's ap_get_basic_auth_pw() API function outside of the authentication phase could lead to authentication bypass. A remote attacker could possibly use this flaw to bypass required authentication if the API was used incorrectly by one of the modules used by httpd. (CVE-2017-3167)

  • A NULL pointer dereference flaw was found in the httpd's mod_ssl module. A remote attacker could use this flaw to cause an httpd child process to crash if another module used by httpd called a certain API function during the processing of an HTTPS request. (CVE-2017-3169)

  • A buffer over-read flaw was found in the httpd's ap_find_token() function. A remote attacker could use this flaw to cause httpd child process to crash via a specially crafted HTTP request. (CVE-2017-7668)

  • A buffer over-read flaw was found in the httpd's mod_mime module. A user permitted to modify httpd's MIME configuration could use this flaw to cause httpd child process to crash. (CVE-2017-7679)
  • Family:unixClass:patch
    Status:Reference(s):CVE-2017-3167
    CVE-2017-3169
    CVE-2017-7668
    CVE-2017-7679
    CVE-2017-9788
    RHSA-2017:2479
    RHSA-2017:2479-00
    RHSA-2017:2479-01
    Platform(s):Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • httpd is earlier than 0:2.4.6-67.el7_4.2
  • AND httpd is signed with Red Hat redhatrelease2 key
  • httpd-devel is earlier than 0:2.4.6-67.el7_4.2
  • AND httpd-devel is signed with Red Hat redhatrelease2 key
  • httpd-manual is earlier than 0:2.4.6-67.el7_4.2
  • AND httpd-manual is signed with Red Hat redhatrelease2 key
  • httpd-tools is earlier than 0:2.4.6-67.el7_4.2
  • AND httpd-tools is signed with Red Hat redhatrelease2 key
  • mod_ldap is earlier than 0:2.4.6-67.el7_4.2
  • AND mod_ldap is signed with Red Hat redhatrelease2 key
  • mod_proxy_html is earlier than 1:2.4.6-67.el7_4.2
  • AND mod_proxy_html is signed with Red Hat redhatrelease2 key
  • mod_session is earlier than 0:2.4.6-67.el7_4.2
  • AND mod_session is signed with Red Hat redhatrelease2 key
  • mod_ssl is earlier than 1:2.4.6-67.el7_4.2
  • AND mod_ssl is signed with Red Hat redhatrelease2 key
  • BACK