CVE-2016-8743

HIGH

Apache HTTP Server <2.2.32 & 2.4.25 - Info Disclosure

Title source: llm
STIX 2.1

Description

Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and sent in response lines and headers. Accepting these different behaviors represented a security concern when httpd participates in any chain of proxies or interacts with back-end application servers, either through mod_proxy or using conventional CGI mechanisms, and may result in request smuggling, response splitting and cache pollution.

References (40)

Core 40
Core References
Third Party Advisory x_refsource_confirm
https://support.apple.com/HT208221
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2017/dsa-3796
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:1721
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1037508
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:1413
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:1161
Third Party Advisory x_refsource_confirm
https://www.tenable.com/security/tns-2017-04
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:1414
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/95077
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2017-1415.html
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:0906
Patch, Third Party Advisory, VDB Entry vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201701-36
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20180423-0001/

Scores

CVSS v3 7.5
EPSS 0.0978
EPSS Percentile 93.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

Status published
Products (25)
apache/http_server 2.2.0 - 2.2.31
Apache Software Foundation/Apache HTTP Server 2.2.0 to 2.2.31, 2.4.1 to 2.4.23
debian/debian_linux 8.0
debian/debian_linux 9.0
netapp/clustered_data_ontap
netapp/oncommand_unified_manager
redhat/enterprise_linux_desktop 6.0
redhat/enterprise_linux_desktop 7.0
redhat/enterprise_linux_eus 7.3
redhat/enterprise_linux_eus 7.4
... and 15 more
Published Jul 27, 2017
Tracked Since Feb 18, 2026