PublicDateAtUSN: 2016-12-22 Candidate: CVE-2016-8743 PublicDate: 2017-07-27 21:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8743 https://lists.apache.org/thread.html/139862b41c0dfd5e6e00ad89c00119f9faf0dd41a2f927da9c9a4076@%3Cannounce.httpd.apache.org%3E https://httpd.apache.org/security/vulnerabilities_24.html https://ubuntu.com/security/notices/USN-3279-1 https://ubuntu.com/security/notices/USN-3373-1 Description: Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and sent in response lines and headers. Accepting these different behaviors represented a security concern when httpd participates in any chain of proxies or interacts with back-end application servers, either through mod_proxy or using conventional CGI mechanisms, and may result in request smuggling, response splitting and cache pollution. Ubuntu-Description: Notes: ratliff> Notes from Debian "The fix is not fully backwards compatible so ratliff> upstream have created a new option to control this behaviour. ratliff> Affects: 2.2.0 to 2.4.23." mdeslaur> mdeslaur> This fix no longer allows underscores in host names. Debian mdeslaur> added a patch to restore the behaviour: mdeslaur> https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=851357 mdeslaur> http://mail-archives.apache.org/mod_mbox/httpd-dev/201702.mbox/%3C20170202125319.GA15948%40redhat.com%3E mdeslaur> mdeslaur> The new configuration option doesn't entirely preserve mdeslaur> backwards compatibility: mdeslaur> https://bz.apache.org/bugzilla/show_bug.cgi?id=60783 Bugs: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=847124 Priority: medium Discovered-by: David Dennerline and Régis Leroy Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N [7.5 HIGH] Patches_apache2: upstream: https://svn.apache.org/r1668879 (2.4 bp, trusty) upstream: https://svn.apache.org/r1743516 (2.4 bp) upstream: https://svn.apache.org/r1773801 (2.4 bp) upstream: https://svn.apache.org/r1772678 (2.4) upstream: https://svn.apache.org/r1773802 (2.4) upstream: https://svn.apache.org/r1773803 (2.4) upstream: https://svn.apache.org/r1773995 (2.4) upstream: https://svn.apache.org/r1774429 (2.4) upstream: https://svn.apache.org/r1778052 (2.4) upstream_apache2: released (2.4.25-1) precise_apache2: ignored (reached end-of-life) precise/esm_apache2: released (2.2.22-1ubuntu1.12) trusty_apache2: released (2.4.7-1ubuntu4.14) trusty/esm_apache2: released (2.4.7-1ubuntu4.14) vivid/stable-phone-overlay_apache2: DNE vivid/ubuntu-core_apache2: DNE xenial_apache2: released (2.4.18-2ubuntu3.2) esm-infra/xenial_apache2: released (2.4.18-2ubuntu3.2) yakkety_apache2: released (2.4.18-2ubuntu4.1) zesty_apache2: not-affected (2.4.25-3ubuntu2) devel_apache2: not-affected (2.4.25-3ubuntu2)