CVE-2017-3169

In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer when third-party modules call ap_hook_process_connection() during an HTTP request to an HTTPS port.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
apacheCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
VendorProductVersion
apachehttp_server
2.2.0
apachehttp_server
2.2.2
apachehttp_server
2.2.3
apachehttp_server
2.2.11
apachehttp_server
2.2.12
apachehttp_server
2.2.13
apachehttp_server
2.2.14
apachehttp_server
2.2.15
apachehttp_server
2.2.16
apachehttp_server
2.2.17
apachehttp_server
2.2.18
apachehttp_server
2.2.19
apachehttp_server
2.2.20
apachehttp_server
2.2.21
apachehttp_server
2.2.22
apachehttp_server
2.2.23
apachehttp_server
2.2.24
apachehttp_server
2.2.25
apachehttp_server
2.2.26
apachehttp_server
2.2.27
apachehttp_server
2.2.29
apachehttp_server
2.2.30
apachehttp_server
2.2.31
apachehttp_server
2.2.32
apachehttp_server
2.4.1
apachehttp_server
2.4.2
apachehttp_server
2.4.10
apachehttp_server
2.4.12
apachehttp_server
2.4.16
apachehttp_server
2.4.17
apachehttp_server
2.4.18
apachehttp_server
2.4.20
apachehttp_server
2.4.23
apachehttp_server
2.4.25
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
apache2
bullseye
2.4.62-1~deb11u1
fixed
bullseye (security)
2.4.62-1~deb11u2
fixed
bookworm
2.4.62-1~deb12u1
fixed
bookworm (security)
2.4.62-1~deb12u2
fixed
sid
2.4.62-3
fixed
trixie
2.4.62-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
apache2
zesty
Fixed 2.4.25-3ubuntu2.1
released
yakkety
Fixed 2.4.18-2ubuntu4.2
released
xenial
Fixed 2.4.18-2ubuntu3.3
released
trusty
Fixed 2.4.7-1ubuntu4.16
released
References