oss-sec mailing list archives
CVE-2017-3169: Apache httpd 2.x mod_ssl null pointer dereference
From: Jacob Champion <jchampion () apache org>
Date: Mon, 19 Jun 2017 15:16:21 -0700
CVE-2017-3169: mod_ssl null pointer dereference Severity: Important Vendor: The Apache Software Foundation Versions Affected: httpd 2.2.0 to 2.2.32 httpd 2.4.0 to 2.4.25 Description: mod_ssl may dereference a NULL pointer when third-party modules call ap_hook_process_connection() during an HTTP request to an HTTPS port. Mitigation: 2.2.x users should either apply the patch available at https://www.apache.org/dist/httpd/patches/apply_to_2.2.32/CVE-2017-3169.patch or upgrade in the future to 2.2.33, which is currently unreleased. 2.4.x users should upgrade to 2.4.26. Credit: The Apache HTTP Server security team would like to thank Vasileios Panopoulos and AdNovum Informatik AG for reporting this issue. References: https://httpd.apache.org/security_report.html
Current thread:
- CVE-2017-3169: Apache httpd 2.x mod_ssl null pointer dereference Jacob Champion (Jun 19)