Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-8612

Опубликовано: 15 дек. 2016
Источник: redhat
CVSS3: 4.3
CVSS2: 2.9
EPSS Низкий

Описание

Apache HTTP Server mod_cluster before version httpd 2.4.23 is vulnerable to an Improper Input Validation in the protocol parsing logic in the load balancer resulting in a Segmentation Fault in the serving httpd process.

An error was found in protocol parsing logic of mod_cluster load balancer Apache HTTP Server modules. An attacker could use this flaw to cause a Segmentation Fault in the serving httpd process.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Application Platform 5mod_clusterWill not fix
Red Hat JBoss Enterprise Application Platform 6mod_clusterWill not fix
Red Hat JBoss Enterprise Application Platform 7mod_clusterNot affected
Red Hat JBoss Enterprise Web Server 2mod_clusterWill not fix
Red Hat JBoss Enterprise Web Server 3mod_clusterAffected
JBoss Core Services on RHEL 6jbcs-httpd24-httpdFixedRHSA-2017:019325.01.2017
JBoss Core Services on RHEL 6jbcs-httpd24-mod_auth_kerbFixedRHSA-2017:019325.01.2017
JBoss Core Services on RHEL 6jbcs-httpd24-mod_bmxFixedRHSA-2017:019325.01.2017
JBoss Core Services on RHEL 6jbcs-httpd24-mod_cluster-nativeFixedRHSA-2017:019325.01.2017
JBoss Core Services on RHEL 6jbcs-httpd24-mod_jkFixedRHSA-2017:019325.01.2017

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1387605mod_cluster: Protocol parsing logic error

EPSS

Процентиль: 80%
0.01319
Низкий

4.3 Medium

CVSS3

2.9 Low

CVSS2

Связанные уязвимости

CVSS3: 4.3
nvd
почти 8 лет назад

Apache HTTP Server mod_cluster before version httpd 2.4.23 is vulnerable to an Improper Input Validation in the protocol parsing logic in the load balancer resulting in a Segmentation Fault in the serving httpd process.

CVSS3: 4.3
debian
почти 8 лет назад

Apache HTTP Server mod_cluster before version httpd 2.4.23 is vulnerab ...

CVSS3: 4.3
github
больше 3 лет назад

Apache HTTP Server mod_cluster before version httpd 2.4.23 is vulnerable to an Improper Input Validation in the protocol parsing logic in the load balancer resulting in a Segmentation Fault in the serving httpd process.

EPSS

Процентиль: 80%
0.01319
Низкий

4.3 Medium

CVSS3

2.9 Low

CVSS2