Red Hat Bugzilla – Bug 1493056
CVE-2017-12171 httpd: # character matches all IPs
Last modified: 2018-02-12 06:32:26 EST
httpd in RHEL 6.9 does not properly parse comments, resulting in the '#' character in "Allow" statements to accidentally match all IP addresses. This can lead to a bypass of intended security restrictions. https://bugzilla.redhat.com/show_bug.cgi?id=1489849
Acknowledgments: Name: KAWAHARA Masashi
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2017:2972 https://access.redhat.com/errata/RHSA-2017:2972