Bug 1406744 (CVE-2016-0736)
Summary: | CVE-2016-0736 httpd: Padding Oracle in Apache mod_session_crypto | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Adam Mariš <amaris> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | apmukher, bbaranow, bkundal, bmaxwell, carnil, cdewolf, csutherl, dandread, darran.lofthouse, dosoudil, fnasser, gzaronik, hhorak, huwang, jason.greene, jawilson, jboss-set, jclere, jdoyle, jkaluza, jorton, lgao, luhliari, mbabacek, mdshaikh, me, mfrodl, mturk, myarboro, pahan, pgier, pragshar, psakar, pslavice, rmeggins, rnetuka, rsvoboda, sardella, twalsh, vtunka, weli |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | httpd 2.4.25 | Doc Type: | If docs needed, set a value |
Doc Text: |
It was discovered that the mod_session_crypto module of httpd did not use any mechanisms to verify integrity of the encrypted session data stored in the user's browser. A remote attacker could use this flaw to decrypt and modify session data using a padding oracle attack.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2017-07-13 05:30:56 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1406823, 1412975, 1412976, 1425463 | ||
Bug Blocks: | 1406828, 1457678 |
Description
Adam Mariš
2016-12-21 11:33:21 UTC
Created httpd tracking bugs for this issue: Affects: fedora-all [bug 1406823] References: http://seclists.org/fulldisclosure/2016/Dec/74 Upstream commit: http://svn.apache.org/viewvc?view=revision&revision=1772925 This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2017:0906 https://access.redhat.com/errata/RHSA-2017:0906 This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 6 Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7 Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS Via RHSA-2017:1161 https://access.redhat.com/errata/RHSA-2017:1161 This issue has been addressed in the following products: Red Hat JBoss Core Services Via RHSA-2017:1415 https://access.redhat.com/errata/RHSA-2017:1415 This issue has been addressed in the following products: JBoss Core Services on RHEL 6 Via RHSA-2017:1414 https://access.redhat.com/errata/RHSA-2017:1414 This issue has been addressed in the following products: JBoss Core Services on RHEL 7 Via RHSA-2017:1413 https://access.redhat.com/errata/RHSA-2017:1413 |