Количество 9
Количество 9
GHSA-mcc7-rcr3-2rgr
The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence of request headers, an attacker may be able to cause a segmentation fault, or to force ap_find_token() to return an incorrect value.
CVE-2017-7668
The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence of request headers, an attacker may be able to cause a segmentation fault, or to force ap_find_token() to return an incorrect value.
CVE-2017-7668
The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence of request headers, an attacker may be able to cause a segmentation fault, or to force ap_find_token() to return an incorrect value.
CVE-2017-7668
The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence of request headers, an attacker may be able to cause a segmentation fault, or to force ap_find_token() to return an incorrect value.
CVE-2017-7668
The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.2 ...
BDU:2017-02150
Уязвимость функции ap_find_token веб-сервера Apache HTTP Server, позволяющая нарушителю вызвать ошибку сегментации
ELSA-2017-2479
ELSA-2017-2479: httpd security update (IMPORTANT)
ELSA-2017-2483
ELSA-2017-2483: httpd24-httpd security update (IMPORTANT)
SUSE-SU-2017:2907-1
Security update for apache2
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-mcc7-rcr3-2rgr The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence of request headers, an attacker may be able to cause a segmentation fault, or to force ap_find_token() to return an incorrect value. | CVSS3: 7.5 | 69% Средний | больше 3 лет назад | |
CVE-2017-7668 The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence of request headers, an attacker may be able to cause a segmentation fault, or to force ap_find_token() to return an incorrect value. | CVSS3: 7.5 | 69% Средний | больше 8 лет назад | |
CVE-2017-7668 The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence of request headers, an attacker may be able to cause a segmentation fault, or to force ap_find_token() to return an incorrect value. | CVSS3: 6.5 | 69% Средний | больше 8 лет назад | |
CVE-2017-7668 The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence of request headers, an attacker may be able to cause a segmentation fault, or to force ap_find_token() to return an incorrect value. | CVSS3: 7.5 | 69% Средний | больше 8 лет назад | |
CVE-2017-7668 The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.2 ... | CVSS3: 7.5 | 69% Средний | больше 8 лет назад | |
BDU:2017-02150 Уязвимость функции ap_find_token веб-сервера Apache HTTP Server, позволяющая нарушителю вызвать ошибку сегментации | CVSS3: 9.8 | 69% Средний | больше 8 лет назад | |
ELSA-2017-2479 ELSA-2017-2479: httpd security update (IMPORTANT) | около 8 лет назад | |||
ELSA-2017-2483 ELSA-2017-2483: httpd24-httpd security update (IMPORTANT) | около 8 лет назад | |||
SUSE-SU-2017:2907-1 Security update for apache2 | около 8 лет назад |
Уязвимостей на страницу