Apache HTTP Server CVE-2017-12171 Security Bypass Vulnerability
BID:101516
CVE-2017-12171 |Info
Apache HTTP Server CVE-2017-12171 Security Bypass Vulnerability
| Bugtraq ID: | 101516 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2017-12171 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 19 2017 12:00AM |
| Updated: | Oct 19 2017 12:00AM |
| Credit: | KAWAHARA Masashi |
| Vulnerable: |
Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux for Scientific Computing 6 Redhat Enterprise Linux for Power, big endian 6 Redhat Enterprise Linux for IBM z Systems 6 Redhat Enterprise Linux Desktop 6 Apache Apache 2.4.26 Apache Apache 2.4.25 Apache Apache 2.4.23 Apache Apache 2.4.20 Apache Apache 2.4.19 Apache Apache 2.4.18 Apache Apache 2.4.16 Apache Apache 2.4.14 Apache Apache 2.4.12 Apache Apache 2.4.11 Apache Apache 2.4.10 Apache Apache 2.4.5 Apache Apache 2.4.4 Apache Apache 2.2.34 Apache Apache 2.2.4 Apache Apache 2.4.9 Apache Apache 2.4.8 Apache Apache 2.4.7 Apache Apache 2.4.6 Apache Apache 2.4.3 Apache Apache 2.4.27 Apache Apache 2.4.24 Apache Apache 2.4.2 Apache Apache 2.4.13 Apache Apache 2.4.1 Apache Apache 2.4.0 |
| Not Vulnerable: | |
Discussion
Apache HTTP Server CVE-2017-12171 Security Bypass Vulnerability
Apache HTTP Server is prone to a security bypass vulnerability.
An attacker can exploit this issue to bypass security restrictions and perform unauthorized actions. This may aid in further attacks.
Apache HTTP Server is prone to a security bypass vulnerability.
An attacker can exploit this issue to bypass security restrictions and perform unauthorized actions. This may aid in further attacks.
Exploit / POC
Apache HTTP Server CVE-2017-12171 Security Bypass Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apache HTTP Server CVE-2017-12171 Security Bypass Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Apache HTTP Server CVE-2017-12171 Security Bypass Vulnerability
References:
References:
- Apache Homepage (Apache)
- Bug 1493056 - (CVE-2017-12171) CVE-2017-12171 httpd: # character matches all IP (Redhat)
- CVE-2017-12171 (Redhat)
- RHSA-2017:2972: - Security Advisory (Redhat)