RHSA-2017:3193: Important: httpd security update
The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.<br>Security Fix(es):<br><li> It was discovered that the httpd's modauthdigest module did not properly initialize memory before using it when processing certain headers related to digest authentication. A remote attacker could possibly use this flaw to disclose potentially sensitive information or cause httpd child process to crash by sending specially crafted requests to a server. (CVE-2017-9788)</li> <li> It was discovered that the use of httpd's apgetbasicauthpw() API function outside of the authentication phase could lead to authentication bypass. A remote attacker could possibly use this flaw to bypass required authentication if the API was used incorrectly by one of the modules used by httpd. (CVE-2017-3167)</li> <li> A NULL pointer dereference flaw was found in the httpd's modssl module. A remote attacker could use this flaw to cause an httpd child process to crash if another module used by httpd called a certain API function during the processing of an HTTPS request. (CVE-2017-3169)</li> <li> A buffer over-read flaw was found in the httpd's apfindtoken() function. A remote attacker could use this flaw to cause httpd child process to crash via a specially crafted HTTP request. (CVE-2017-7668)</li> <li> A buffer over-read flaw was found in the httpd's modmime module. A user permitted to modify httpd's MIME configuration could use this flaw to cause httpd child process to crash. (CVE-2017-7679)</li> <li> A use-after-free flaw was found in the way httpd handled invalid and previously unregistered HTTP methods specified in the Limit directive used in an .htaccess file. A remote attacker could possibly use this flaw to disclose portions of the server memory, or cause httpd child process to crash. (CVE-2017-9798)</li> Red Hat would like to thank Hanno Böck for reporting CVE-2017-9798.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2017:3193?
The severity of RHSA-2017:3193 is categorized as moderate.
How do I fix RHSA-2017:3193?
To fix RHSA-2017:3193, you should upgrade the httpd package to version 2.4.6-40.el7_2.6 or later.
What is RHSA-2017:3193 about?
RHSA-2017:3193 addresses a memory initialization flaw in the mod_auth_digest module of the httpd package.
Which packages are affected by RHSA-2017:3193?
RHSA-2017:3193 affects several httpd packages, including httpd, httpd-devel, and httpd-tools, among others.
Is RHSA-2017:3193 applicable to all systems?
RHSA-2017:3193 is specifically applicable to systems running the affected versions of Red Hat's httpd package.