CVE-2017-3169
CRITICALApache HTTP Server 2.2.x < 2.2.33 and 2.4.x < 2.4.26 - NULL Pointer Dereference in mod_ssl
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2017-3169. PoCs published by vaishakhcv, winterwolf32.
AI-analyzed exploit summary This repository contains a functional Perl exploit for CVE-2017-3169, a NULL pointer dereference vulnerability in Apache httpd's mod_ssl. The exploit triggers a DoS by sending crafted requests to an HTTPS port, leveraging a third-party module to call ap_hook_process_connection during an HTTP request.
Description
In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer when third-party modules call ap_hook_process_connection() during an HTTP request to an HTTPS port.
Exploits (2)
This repository contains a functional Perl exploit for CVE-2017-3169, a NULL pointer dereference vulnerability in Apache httpd's mod_ssl. The exploit triggers a DoS by sending crafted requests to an HTTPS port, leveraging a third-party module to call ap_hook_process_connection during an HTTP request.
The repository contains a functional Perl exploit for CVE-2017-3169, a NULL pointer dereference vulnerability in Apache httpd's mod_ssl. The exploit triggers a DoS by sending crafted requests to an HTTPS port, leveraging a third-party module to call ap_hook_process_connection during an HTTP request.
References (42)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H