CVE-2016-4979: High severity Apache HTTP Server vulnerability

Published Jul 4, 2016
·
Updated

The Apache HTTP Server 2.4.18 through 2.4.20, when modhttp2 and modssl are enabled, does not properly recognize the "SSLVerifyClient require" directive for HTTP/2 request authorization, which allows remote attackers to bypass intended access restrictions by leveraging the ability to send multiple requests over a single connection and aborting a renegotiation.

Other sources

The Apache HTTPD web server (from 2.4.18/r1715255 up to 2.4.23/r1750779) did not validate a X509 client certificate correctly when HTTP/2 is used to access a resource.

As a result - a resource thought to be secure and requiring a valid client certificate - would be accessible without authentication provided that the modhttp2 was loaded, h2 or h2c activated, that that the browser used the HTTP/2 protocol and it would do more than one request over a given connection. A third party can gain access to resources on the web server without the requisite credentials. This can then lead to unauthorised disclosure of information.

This issue has been fixed in version 2.4.23 (r1750779).

As a temporary workaround - HTTP/2 can be disabled by changing the configuration by removing h2 and h2c from the Protocols line(s) in the configuration file.

The resulting line should read:

Protocols http/1.1

Red Hat

Affected Software

4 affected componentsFixes available
redhat/httpd<2.4.23
2.4.23
Apache HTTP Server=2.4.18
Apache HTTP Server=2.4.19
Apache HTTP Server=2.4.20

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/httpd to a version that resolves this vulnerability.

    Fixed in 2.4.23
  2. Upgrade

    Upgrade Apache HTTP Server to a version that resolves this vulnerability.

    Fixed in 2.4.23Patch r1750779
  3. Configuration

    As a temporary workaround, disable HTTP/2 by removing 'h2' and 'h2c' from the Protocols line(s) in the Apache configuration file (the resulting line should read 'Protocols http/1.1').

    Apache HTTP Server (mod_http2) Protocols (remove h2 and h2c) = Protocols http/1.1

Event History

Jul 4, 2016
Data Sourced
via Red Hat·09:09 AM
DescriptionSeverityAffected Software
Jul 6, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2016-4979?

CVE-2016-4979 is considered a moderate severity vulnerability that allows bypass of access restrictions.

2

How do I fix CVE-2016-4979?

To fix CVE-2016-4979, upgrade Apache HTTP Server to version 2.4.23 or later.

3

What systems are affected by CVE-2016-4979?

CVE-2016-4979 affects Apache HTTP Server versions 2.4.18 through 2.4.20 with mod_http2 and mod_ssl enabled.

4

What types of attacks can exploit CVE-2016-4979?

CVE-2016-4979 can be exploited by remote attackers to bypass client verification restrictions.

5

Is CVE-2016-4979 related to SSL/TLS security?

Yes, CVE-2016-4979 is related to SSL/TLS security as it involves the misuse of SSLVerifyClient in HTTP/2 requests.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203