CVE-2017-15710: High severity Apache HTTP Server vulnerability

Published Mar 23, 2018
·
Updated

In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, modauthnzldap, if configured with AuthLDAPCharsetConfig, uses the Accept-Language header value to lookup the right charset encoding when verifying the user's credentials. If the header value is not present in the charset conversion table, a fallback mechanism is used to truncate it to a two characters value to allow a quick retry (for example, 'en-US' is truncated to 'en'). A header value of less than two characters forces an out of bound write of one NUL byte to a memory location that is not part of the string. In the worst case, quite unlikely, the process would crash which could be used as a Denial of Service attack. In the more likely case, this memory is already reserved for future use and the issue has no effect at all.

Other sources

modauthnzldap, if configured with AuthLDAPCharsetConfig, uses the Accept-Language header value to lookup the right charset encoding when verifying the user's credentials. If the header value is not present in the charset conversion table, a fallback mechanism is used to truncate it to a two characters value to allow a quick retry (for example, 'en-US' is truncated to 'en'). A header value of less than two characters forces an out of bound write of one NUL byte to a memory location that is not part of the string. In the worst case, quite unlikely, the process would crash which could be used as a Denial of Service attack. In the more likely case, this memory is already reserved for future use and the issue has no effect at all.

Versions Affected: httpd 2.0.23 to 2.0.65 httpd 2.2.0 to 2.2.34 httpd 2.4.0 to 2.4.29

External References:

https://httpd.apache.org/security/vulnerabilities24.html

Red Hat

Affected Software

59 affected componentsFixes available
redhat/jbcs-httpd24<0:1-6.jbcs.el6
0:1-6.jbcs.el6
redhat/jbcs-httpd24-apache-commons-daemon-jsvc<1:1.1.0-3.redhat_2.jbcs.el6
1:1.1.0-3.redhat_2.jbcs.el6
redhat/jbcs-httpd24-apr<0:1.6.3-31.jbcs.el6
0:1.6.3-31.jbcs.el6
redhat/jbcs-httpd24-apr-util<0:1.6.1-24.jbcs.el6
0:1.6.1-24.jbcs.el6
redhat/jbcs-httpd24-httpd<0:2.4.29-35.jbcs.el6
0:2.4.29-35.jbcs.el6
redhat/jbcs-httpd24-nghttp2<0:1.29.0-9.jbcs.el6
0:1.29.0-9.jbcs.el6
redhat/jbcs-httpd24-openssl<1:1.0.2n-14.jbcs.el6
1:1.0.2n-14.jbcs.el6
redhat/jbcs-httpd24<0:1-6.jbcs.el7
0:1-6.jbcs.el7
redhat/jbcs-httpd24-apache-commons-daemon-jsvc<1:1.1.0-3.redhat_2.jbcs.el7
1:1.1.0-3.redhat_2.jbcs.el7
redhat/jbcs-httpd24-apr<0:1.6.3-31.jbcs.el7
0:1.6.3-31.jbcs.el7
redhat/jbcs-httpd24-apr-util<0:1.6.1-24.jbcs.el7
0:1.6.1-24.jbcs.el7
redhat/jbcs-httpd24-httpd<0:2.4.29-35.jbcs.el7
0:2.4.29-35.jbcs.el7
redhat/jbcs-httpd24-nghttp2<0:1.29.0-9.jbcs.el7
0:1.29.0-9.jbcs.el7
redhat/jbcs-httpd24-openssl<1:1.0.2n-14.jbcs.el7
1:1.0.2n-14.jbcs.el7
redhat/httpd<0:2.4.6-93.el7
0:2.4.6-93.el7
redhat/httpd24-curl<0:7.61.1-1.el6
0:7.61.1-1.el6
redhat/httpd24-httpd<0:2.4.34-7.el6
0:2.4.34-7.el6
redhat/httpd24-nghttp2<0:1.7.1-7.el6
0:1.7.1-7.el6
redhat/httpd24-curl<0:7.61.1-1.el7
0:7.61.1-1.el7
redhat/httpd24-httpd<0:2.4.34-7.el7
0:2.4.34-7.el7
redhat/httpd24-nghttp2<0:1.7.1-7.el7
0:1.7.1-7.el7
Apache HTTP Server=2.4.1
Apache HTTP Server=2.4.2
Apache HTTP Server=2.4.3
Apache HTTP Server=2.4.4
Apache HTTP Server=2.4.6
Apache HTTP Server=2.4.7
Apache HTTP Server=2.4.9
Apache HTTP Server=2.4.10
Apache HTTP Server=2.4.12
Apache HTTP Server=2.4.16
Apache HTTP Server=2.4.17
Apache HTTP Server=2.4.18
Apache HTTP Server=2.4.20
Apache HTTP Server=2.4.23
Apache HTTP Server=2.4.25
Apache HTTP Server=2.4.26
Apache HTTP Server=2.4.27
Apache HTTP Server=2.4.28
Apache HTTP Server=2.4.29
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=17.10
Canonical Ubuntu Linux=18.04
NetApp Santricity Cloud Connector
NetApp Storage Automation Store
NetApp Storagegrid
NetApp Clustered Data ONTAP
redhat Enterprise Linux=6.0
redhat Enterprise Linux=7.0
redhat Enterprise Linux=7.4
redhat Enterprise Linux=7.5
redhat Enterprise Linux=7.6
redhat/httpd<2.4.30
2.4.30
debian/apache2
2.4.62-1~deb11u12.4.67-1~deb11u32.4.68-1~deb12u12.4.67-1~deb12u32.4.68-1~deb13u12.4.67-1~deb13u32.4.68-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/jbcs-httpd24 to a version that resolves this vulnerability.

    Fixed in 0:1-6.jbcs.el6
  2. Upgrade

    Upgrade redhat/jbcs-httpd24-apache-commons-daemon-jsvc to a version that resolves this vulnerability.

    Fixed in 1:1.1.0-3.redhat_2.jbcs.el6
  3. Upgrade

    Upgrade redhat/jbcs-httpd24-apr to a version that resolves this vulnerability.

    Fixed in 0:1.6.3-31.jbcs.el6
  4. Upgrade

    Upgrade redhat/jbcs-httpd24-apr-util to a version that resolves this vulnerability.

    Fixed in 0:1.6.1-24.jbcs.el6
  5. Upgrade

    Upgrade redhat/jbcs-httpd24-httpd to a version that resolves this vulnerability.

    Fixed in 0:2.4.29-35.jbcs.el6
  6. Upgrade

    Upgrade redhat/jbcs-httpd24-nghttp2 to a version that resolves this vulnerability.

    Fixed in 0:1.29.0-9.jbcs.el6
  7. Upgrade

    Upgrade redhat/jbcs-httpd24-openssl to a version that resolves this vulnerability.

    Fixed in 1:1.0.2n-14.jbcs.el6
  8. Upgrade

    Upgrade redhat/jbcs-httpd24 to a version that resolves this vulnerability.

    Fixed in 0:1-6.jbcs.el7
  9. Upgrade

    Upgrade redhat/jbcs-httpd24-apache-commons-daemon-jsvc to a version that resolves this vulnerability.

    Fixed in 1:1.1.0-3.redhat_2.jbcs.el7
  10. Upgrade

    Upgrade redhat/jbcs-httpd24-apr to a version that resolves this vulnerability.

    Fixed in 0:1.6.3-31.jbcs.el7
  11. Upgrade

    Upgrade redhat/jbcs-httpd24-apr-util to a version that resolves this vulnerability.

    Fixed in 0:1.6.1-24.jbcs.el7
  12. Upgrade

    Upgrade redhat/jbcs-httpd24-httpd to a version that resolves this vulnerability.

    Fixed in 0:2.4.29-35.jbcs.el7
  13. Upgrade

    Upgrade redhat/jbcs-httpd24-nghttp2 to a version that resolves this vulnerability.

    Fixed in 0:1.29.0-9.jbcs.el7
  14. Upgrade

    Upgrade redhat/jbcs-httpd24-openssl to a version that resolves this vulnerability.

    Fixed in 1:1.0.2n-14.jbcs.el7
  15. Upgrade

    Upgrade redhat/httpd to a version that resolves this vulnerability.

    Fixed in 0:2.4.6-93.el7
  16. Upgrade

    Upgrade redhat/httpd24-curl to a version that resolves this vulnerability.

    Fixed in 0:7.61.1-1.el6
  17. Upgrade

    Upgrade redhat/httpd24-httpd to a version that resolves this vulnerability.

    Fixed in 0:2.4.34-7.el6
  18. Upgrade

    Upgrade redhat/httpd24-nghttp2 to a version that resolves this vulnerability.

    Fixed in 0:1.7.1-7.el6
  19. Upgrade

    Upgrade redhat/httpd24-curl to a version that resolves this vulnerability.

    Fixed in 0:7.61.1-1.el7
  20. Upgrade

    Upgrade redhat/httpd24-httpd to a version that resolves this vulnerability.

    Fixed in 0:2.4.34-7.el7
  21. Upgrade

    Upgrade redhat/httpd24-nghttp2 to a version that resolves this vulnerability.

    Fixed in 0:1.7.1-7.el7
  22. Upgrade

    Upgrade redhat/httpd to a version that resolves this vulnerability.

    Fixed in 2.4.30
  23. Upgrade

    Upgrade debian/apache2 to a version that resolves this vulnerability.

    Fixed in 2.4.62-1~deb11u1Fixed in 2.4.67-1~deb11u3Fixed in 2.4.68-1~deb12u1Fixed in 2.4.67-1~deb12u3Fixed in 2.4.68-1~deb13u1Fixed in 2.4.67-1~deb13u3Fixed in 2.4.68-1
  24. Upgrade

    Upgrade Apache httpd to a version that resolves this vulnerability.

    Fixed in 2.4.30
  25. Configuration

    If mod_authnz_ldap uses AuthLDAPCharsetConfig, remove/disable that configuration so it does not use the Accept-Language header value to look up the charset encoding during credential verification.

    mod_authnz_ldap AuthLDAPCharsetConfig = not configured or disabled
  26. Compensating control

    Mitigate the potential Denial of Service by restricting/limiting exposure to requests that include a malicious Accept-Language header value while the fix is applied.

Event History

Mar 24, 2018
CVE Published
12:00 AM
Mar 26, 2018
Data Sourced
via Red Hat·02:28 PM
DescriptionSeverityAffected Software
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Data Sourced
via NVD·03:29 PM
DescriptionSeverityWeaknessAffected Software
Sep 23, 2025
Data Sourced
via Ubuntu·04:35 AM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·04:35 AM
Description
Jul 16, 2026
Data Sourced
via Debian·11:30 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is the severity of CVE-2017-15710?

CVE-2017-15710 is categorized as a moderate severity vulnerability.

2

How do I fix CVE-2017-15710?

To fix CVE-2017-15710, ensure you are using the patched versions of affected packages, such as apache-commons-daemon, httpd, and openssl, as specified in the remediation information.

3

What software versions are affected by CVE-2017-15710?

CVE-2017-15710 affects Apache HTTP Server versions 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29.

4

What happens if I do not address CVE-2017-15710?

If CVE-2017-15710 is not addressed, unauthorized users may exploit the vulnerability to bypass authentication and gain unauthorized access.

5

Is CVE-2017-15710 specific to certain operating systems?

CVE-2017-15710 can affect various operating systems where Apache HTTPD is installed, particularly on RHEL and Debian based distributions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203