Lucene search

K
f5F5F5:K53437580
HistoryFeb 01, 2017 - 12:00 a.m.

K53437580 : Apache vulnerabilities CVE-2016-0736 and CVE-2016-2161

2017-02-0100:00:00
my.f5.com
57

7.5 High

AI Score

Confidence

High

0.021 Low

EPSS

Percentile

89.2%

Security Advisory Description

In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly either CBC or ECB modes of operation (AES256-CBC by default), hence no selectable or builtin authenticated encryption. This made it vulnerable to padding oracle attacks, particularly with CBC.

In Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to mod_auth_digest can cause the server to crash, and each instance continues to crash even for subsequently valid requests.
Impact
There is no impact; F5 products are not affected by this vulnerability.