Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-17199

Опубликовано: 30 янв. 2019
Источник: debian

Описание

In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time is loaded when the session is decoded.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
apache2fixed2.4.38-1package

Примечания

  • https://www.openwall.com/lists/oss-security/2019/01/22/3

  • 2.4.x http://svn.apache.org/r1851409

  • 2.5.x http://svn.apache.org/r1850947

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time is loaded when the session is decoded.

CVSS3: 5.4
redhat
больше 6 лет назад

In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time is loaded when the session is decoded.

CVSS3: 7.5
nvd
больше 6 лет назад

In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time is loaded when the session is decoded.

CVSS3: 7.5
github
около 3 лет назад

In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time is loaded when the session is decoded.

CVSS3: 7.5
fstec
больше 6 лет назад

Уязвимость модуля mod_session веб-сервера Apache HTTP Server, связанная с отсутствием учета времени жизни сеанса, позволяющая нарушителю оказать воздействие на целостность защищаемых данных