Lucene search

K
nessusTenable9394.PRM
HistoryJul 15, 2016 - 12:00 a.m.

Apache HTTP Server 2.4.x < 2.4.23 Multiple Vulnerabilities

2016-07-1500:00:00
Tenable
www.tenable.com
48

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

0.046 Low

EPSS

Percentile

92.6%

The version of Apache HTTP Server 2.4 installed on the remote host is prior to 2.4.23. It is, therefore, affected by the following vulnerabilities :

  • A flaw exists within the ‘read_request_line()’ function located in ‘server/protocol.c’. The issue is triggered when handling invalid ‘CONNECT’ requests with a custom status ‘code 400 error’ page using server side includes. With a specially crafted request, a remote attacker can cause a crash.
  • A flaw can be triggered when a stream’s flow control windows are manipulated. This may allow an authenticated remote attacker to block server threads for an extended period of time, allowing them to exhaust worker threads and prevent the processing of streams. (CVE-2016-1546) - A flaw is triggered when an experimental module for the ‘HTTP/2’ protocol is used to access a resource. This may result in X.509 certificates not being properly validated, allowing an unauthorized user to disclose potentially sensitive information in resources that should require valid certificates. (CVE-2016-4979)
Binary data 9394.prm
VendorProductVersionCPE
apachehttp_servercpe:/a:apache:http_server

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

0.046 Low

EPSS

Percentile

92.6%