CVE-2015-3185: Low severity Canonical Ubuntu Linux vulnerability
Apache HTTP Server 2.4.16 release fixes the following issue:
) SECURITY: CVE-2015-3185 (cve.mitre.org) Replacement of apsomeauthrequired (unusable in Apache httpd 2.4) with new apsomeauthnrequired and apforceauthn hook. [Ben Reser]
External References:
http://httpd.apache.org/security/vulnerabilities24.html#2.4.16
Other sources
It was discovered that in httpd 2.4, the internal API function apsomeauthrequired() could incorrectly indicate that a request was authenticated even when no authentication was used. An httpd module using this API function could consequently allow access that should have been denied.
The apsomeauthrequired function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging the presence of a module that relies on the 2.2 API behavior.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2015-3185?
CVE-2015-3185 has a moderate severity rating due to its potential impact on authentication requirements.
How do I fix CVE-2015-3185?
To fix CVE-2015-3185, upgrade to Apache HTTP Server versions 2.4.23 or higher.
What software is affected by CVE-2015-3185?
CVE-2015-3185 affects Apache HTTP Server versions prior to 2.4.23, including various Red Hat versions.
Can CVE-2015-3185 lead to unauthorized access?
Yes, CVE-2015-3185 can potentially allow attackers to bypass authentication controls.
Is there a patch available for CVE-2015-3185?
Yes, a patch for CVE-2015-3185 is available in the form of updated packages for affected software.