CVE-2016-8743

NameCVE-2016-8743
DescriptionApache HTTP Request Parsing Whitespace Defects
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-841-1, DSA-3796-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
apache2 (PTS)wheezy2.2.22-13+deb7u6vulnerable
wheezy (security)2.2.22-13+deb7u10fixed
jessie2.4.10-10+deb8u9fixed
jessie (security)2.4.10-10+deb8u10fixed
stretch2.4.25-3+deb9u1fixed
stretch (security)2.4.25-3+deb9u2fixed
buster, sid2.4.27-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
apache2source(unstable)2.4.25-1
apache2sourcejessie2.4.10-10+deb8u8DSA-3796-1
apache2sourcewheezy2.2.22-13+deb7u8DLA-841-1

Notes

https://lists.apache.org/thread.html/139862b41c0dfd5e6e00ad89c00119f9faf0dd41a2f927da9c9a4076@%3Cannounce.httpd.apache.org%3E
https://httpd.apache.org/security/vulnerabilities_24.html
The fix is not fully backwards compatible so upstream have
created a new option to control this behaviour. This means that
if this is fixed the security advisory need to mention this.
The fix is invasive and should require some extra testing before reaching
stable and old-stable.
Affects: 2.2.0 to 2.4.23.
Fixed in 2.4.25.
For 2.2 preparation is done in http://svn.apache.org/viewvc/httpd/httpd/branches/2.2.x-merge-http-strict/

Search for package or bug name: Reporting problems