Oval Definition:oval:com.ubuntu.xenial:def:201813120000000
Revision Date:2018-03-26Version:1
Title:CVE-2018-1312 on Ubuntu 16.04 LTS (xenial) - low.
Description:In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests could be replayed across servers by an attacker without detection.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2018-1312
Platform(s):Ubuntu 16.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 16.04 LTS (xenial) is installed.
  • AND apache2 package in xenial was vulnerable but has been fixed (note: '2.4.18-2ubuntu3.8').
  • BACK