5
MEDIUM

CVE-2018-17199

Published: 30/01/2019 Updated: 15/02/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9

Vulnerability Summary

In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time is loaded when the session is decoded.

Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N
Access Complexity: LOW
Authentication: NONE
Access Vector: NETWORK
Confidentiality Impact: NONE
Integrity Impact: PARTIAL
Availability Impact: NONE

Vulnerability Trend

Affected Products

Vendor Product Versions
ApacheHttp Server2.4.0, 2.4.1, 2.4.2, 2.4.3, 2.4.4, 2.4.6, 2.4.7, 2.4.8, 2.4.9, 2.4.10, 2.4.12, 2.4.14, 2.4.16, 2.4.17, 2.4.18, 2.4.19, 2.4.20, 2.4.21, 2.4.22, 2.4.23, 2.4.24, 2.4.25, 2.4.26, 2.4.27, 2.4.28, 2.4.29, 2.4.32, 2.4.33, 2.4.34, 2.4.35, 2.4.36, 2.4.37
NetappSantricity Cloud Connector-
DebianDebian Linux8.0

Vendor Advisories

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem When the candidate has been publicized, the details for this candidate will be provided ...
In Apache HTTP Server 24 release 2437 and prior, mod_session checks the session expiry time before decoding the session This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time is loaded when the session is decoded ...
A bug exists in the way mod_ssl handled client renegotiations A remote attacker could send a carefully crafted request that would cause mod_ssl to enter a loop leading to a denial of service This bug can be only triggered with Apache HTTP Server version 2437 when using OpenSSL version 111 or later, due to an interaction in changes to handling ...
Arch Linux Security Advisory ASA-201901-14 ========================================== Severity: High Date : 2019-01-24 CVE-ID : CVE-2018-17189 CVE-2018-17199 CVE-2019-0190 Package : apache Type : multiple issues Remote : Yes Link : securityarchlinuxorg/AVG-857 Summary ======= The package apache before version 2438-1 is vul ...
There is a vulnerability in the IBM HTTP Server used by WebSphere Application Server ...

Mailing Lists

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] httpd (SSA:2019-022-01) New httpd packages are available for Slackware 140, 141, 142, and -current to fix security issues Here are the details from the Slackware 142 ChangeLog: +--------------------------+ patches/packages/httpd-2438-i586-1_slack142txz: Upgraded Th ...

References