ZeroHour

CVE-2017-7668

CVSS 3.1
7.5 high
EPSS
57%p99
Published
()
Modified
Description

The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence of request headers, an attacker may be able to cause a segmentation fault, or to force ap_find_token() to return an incorrect value.

Vendors
apachenetappredhatdebianoracleapple
Products
http server, clustered data ontap, oncommand unified manager, storagegrid, enterprise linux desktop, enterprise linux eus, enterprise linux server, enterprise linux server aus, enterprise linux server tus, enterprise linux workstation, debian linux, secure global desktop
Weakness
CWE-126, CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news