PublicDateAtUSN: 2016-12-22 Candidate: CVE-2016-0736 PublicDate: 2017-07-27 21:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0736 https://lists.apache.org/thread.html/139862b41c0dfd5e6e00ad89c00119f9faf0dd41a2f927da9c9a4076@%3Cannounce.httpd.apache.org%3E https://httpd.apache.org/security/vulnerabilities_24.html https://ubuntu.com/security/notices/USN-3279-1 Description: In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly either CBC or ECB modes of operation (AES256-CBC by default), hence no selectable or builtin authenticated encryption. This made it vulnerable to padding oracle attacks, particularly with CBC. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N [7.5 HIGH] Patches_apache2: upstream: https://svn.apache.org/viewvc?view=revision&revision=1772812 (trunk) upstream: https://svn.apache.org/viewvc?view=revision&revision=1772925 (2.4) upstream_apache2: released (2.4.25-1) precise_apache2: not-affected (2.2.22-1ubuntu1.11) trusty_apache2: released (2.4.7-1ubuntu4.14) trusty/esm_apache2: released (2.4.7-1ubuntu4.14) vivid/stable-phone-overlay_apache2: DNE vivid/ubuntu-core_apache2: DNE xenial_apache2: released (2.4.18-2ubuntu3.2) esm-infra/xenial_apache2: released (2.4.18-2ubuntu3.2) yakkety_apache2: released (2.4.18-2ubuntu4.1) zesty_apache2: not-affected (2.4.25-3ubuntu2) devel_apache2: not-affected (2.4.25-3ubuntu2)