NA

CVE-2023-38709

Published: 04/04/2024 Updated: 19/04/2024

Vulnerability Summary

Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: up to and including 2.4.58.

Vendor Advisories

Debian Bug report logs - #1068412 apache2: CVE-2024-27316 CVE-2024-24795 CVE-2023-38709 Package: src:apache2; Maintainer for src:apache2 is Debian Apache Maintainers <debian-apache@listsdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Thu, 4 Apr 2024 18:54:02 UTC Severity: grave Tags: security, u ...
Description<!---->A flaw was found in httpd The response headers are not sanitized before an HTTP response is sent when a malicious backend can insert a Content-Type, Content-Encoding or some other headers, resulting in a HTTP response splittingA flaw was found in httpd The response headers are not sanitized before an HTTP response is sent when ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> CVE-2023-38709: Apache HTTP Server: HTTP response splitting <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Eric ...