CVE-2015-3185: Low severity Canonical Ubuntu Linux vulnerability

Published Jul 15, 2015
·
Updated

Apache HTTP Server 2.4.16 release fixes the following issue:

) SECURITY: CVE-2015-3185 (cve.mitre.org) Replacement of apsomeauthrequired (unusable in Apache httpd 2.4) with new apsomeauthnrequired and apforceauthn hook. [Ben Reser]

External References:

http://httpd.apache.org/security/vulnerabilities24.html#2.4.16

Other sources

It was discovered that in httpd 2.4, the internal API function apsomeauthrequired() could incorrectly indicate that a request was authenticated even when no authentication was used. An httpd module using this API function could consequently allow access that should have been denied.

The apsomeauthrequired function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging the presence of a module that relies on the 2.2 API behavior.

Affected Software

26 affected componentsFixes available
redhat/jbcs-httpd24-httpd<0:2.4.23-122.jbcs.el6
0:2.4.23-122.jbcs.el6
redhat/jbcs-httpd24-openssl<1:1.0.2h-14.jbcs.el6
1:1.0.2h-14.jbcs.el6
redhat/jbcs-httpd24-httpd<0:2.4.23-122.jbcs.el7
0:2.4.23-122.jbcs.el7
redhat/jbcs-httpd24-openssl<1:1.0.2h-14.jbcs.el7
1:1.0.2h-14.jbcs.el7
redhat/httpd<0:2.4.6-31.el7_1.1
0:2.4.6-31.el7_1.1
redhat/httpd24-httpd<0:2.4.12-4.el6.2
0:2.4.12-4.el6.2
redhat/httpd24-httpd<0:2.4.12-6.el7.1
0:2.4.12-6.el7.1
redhat/httpd<2.4.16
2.4.16
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.04
Apache HTTP Server=2.4.0
Apache HTTP Server=2.4.1
Apache HTTP Server=2.4.2
Apache HTTP Server=2.4.3
Apache HTTP Server=2.4.4
Apache HTTP Server=2.4.6
Apache HTTP Server=2.4.7
Apache HTTP Server=2.4.8
Apache HTTP Server=2.4.9
Apache HTTP Server=2.4.10
Apache HTTP Server=2.4.12
Apache HTTP Server=2.4.13
Apple Xcode=7.0
Apple iOS and macOS=10.10.4
Apple Mac OS X Server=5.0.3

Event History

Jul 15, 2015
CVE Published
12:00 AM
Jul 16, 2015
Data Sourced
via Red Hat·02:00 PM
DescriptionSeverityAffected Software
Jul 20, 2015
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2015-3185?

CVE-2015-3185 has a moderate severity rating due to its potential impact on authentication requirements.

2

How do I fix CVE-2015-3185?

To fix CVE-2015-3185, upgrade to Apache HTTP Server versions 2.4.23 or higher.

3

What software is affected by CVE-2015-3185?

CVE-2015-3185 affects Apache HTTP Server versions prior to 2.4.23, including various Red Hat versions.

4

Can CVE-2015-3185 lead to unauthorized access?

Yes, CVE-2015-3185 can potentially allow attackers to bypass authentication controls.

5

Is there a patch available for CVE-2015-3185?

Yes, a patch for CVE-2015-3185 is available in the form of updated packages for affected software.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203