CVE-2016-2161

Description

In Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to mod_auth_digest can cause the server to crash, and each instance continues to crash even for subsequently valid requests.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
39.609

Associated Vulnerability

VulnerabilityOS Platform
Update Apache to version 2.4.25Windows
Multiple vulnerabilities fixed in Apache Apache 2.4.25Windows
Vulnerabilities CVE-2016-0736,CVE-2016-2161,CVE-2020-11985 are fixed in Apache 2.4.2Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.2.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.2.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.3.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.3.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.4.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.1Windows
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.6 - Reboot AutomaticallyMac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.6 Combo Update - Reboot AutomaticallyMac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.5 - Reboot AutomaticallyMac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.4 - Reboot AutomaticallyMac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.4 Combo Update - Reboot AutomaticallyMac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.3Mac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.3 Combo UpdateMac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.2Mac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.2 Combo UpdateMac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.1Mac
Multiple vulnerabilities are fixed in Security Update 2017-001 macOS High Sierra v10.13.1Mac
Multiple vulnerabilities are fixed in Security Update 2017-001 macOS High Sierra v10.13Mac
Apache HTTP server (USN-3279-1) apache2-bin_2.4.18-2ubuntu3.2_i386.debLinux
Apache HTTP server (USN-3279-1) apache2-bin_2.4.18-2ubuntu3.2_amd64.debLinux
Apache HTTP server (USN-3279-1) apache2-bin_2.4.18-2ubuntu4.1_i386.debLinux
Apache HTTP server (USN-3279-1) apache2-bin_2.4.18-2ubuntu4.1_amd64.debLinux
Apache HTTP server (USN-3279-1) apache2-bin_2.4.7-1ubuntu4.14_i386.debLinux
Apache HTTP server (USN-3279-1) apache2-bin_2.4.7-1ubuntu4.14_amd64.debLinux
apache2 security update(DSA-3796-1) apache2_2.4.10-10+deb8u8_i386.debLinux
apache2 security update(DSA-3796-1) apache2_2.4.10-10+deb8u8_kfreebsd-i386.debLinux
apache2 security update(DSA-3796-1) apache2_2.4.10-10+deb8u8_kfreebsd-amd64.debLinux
SUSE-SU-2017:0801-1(SUSE Linux Enterprise Server 12-SP1 ) apache2-2.4.16-19.1.x86_64.rpmLinux
SUSE-SU-2017:0801-1(SUSE Linux Enterprise Server 12-SP1 ) apache2-debuginfo-2.4.16-19.1.x86_64.rpmLinux
SUSE-SU-2017:0801-1(SUSE Linux Enterprise Server 12-SP1 ) apache2-debugsource-2.4.16-19.1.x86_64.rpmLinux
SUSE-SU-2017:0801-1(SUSE Linux Enterprise Server 12-SP1 ) apache2-doc-2.4.16-19.1.noarch.rpmLinux
SUSE-SU-2017:0801-1(SUSE Linux Enterprise Server 12-SP1 ) apache2-example-pages-2.4.16-19.1.x86_64.rpmLinux
SUSE-SU-2017:0801-1(SUSE Linux Enterprise Server 12-SP1 ) apache2-prefork-2.4.16-19.1.x86_64.rpmLinux
SUSE-SU-2017:0801-1(SUSE Linux Enterprise Server 12-SP1 ) apache2-prefork-debuginfo-2.4.16-19.1.x86_64.rpmLinux
SUSE-SU-2017:0801-1(SUSE Linux Enterprise Server 12-SP1 ) apache2-utils-2.4.16-19.1.x86_64.rpmLinux
SUSE-SU-2017:0801-1(SUSE Linux Enterprise Server 12-SP1 ) apache2-utils-debuginfo-2.4.16-19.1.x86_64.rpmLinux
SUSE-SU-2017:0801-1(SUSE Linux Enterprise Server 12-SP1 ) apache2-worker-2.4.16-19.1.x86_64.rpmLinux
SUSE-SU-2017:0801-1(SUSE Linux Enterprise Server 12-SP1 ) apache2-worker-debuginfo-2.4.16-19.1.x86_64.rpmLinux
Update Apache to version 2.4.25 (For Linux)Linux
Multiple vulnerabilities fixed in Apache Apache 2.4.25 (For Linux)Linux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-601562macOS High Sierra 10.13.6 - Reboot Automatically
PATCH-601563macOS High Sierra 10.13.6 Combo Update - Reboot Automatically
PATCH-601563macOS High Sierra 10.13.6 Combo Update - Reboot Automatically
PATCH-601562macOS High Sierra 10.13.6 - Reboot Automatically
PATCH-601563macOS High Sierra 10.13.6 Combo Update - Reboot Automatically
PATCH-601562macOS High Sierra 10.13.6 - Reboot Automatically
PATCH-601563macOS High Sierra 10.13.6 Combo Update - Reboot Automatically
PATCH-601562macOS High Sierra 10.13.6 - Reboot Automatically
PATCH-601563macOS High Sierra 10.13.6 Combo Update - Reboot Automatically
PATCH-601562macOS High Sierra 10.13.6 - Reboot Automatically
PATCH-601312Security Update 2017-001 macOS High Sierra v10.13.1
PATCH-601345Security Update 2017-001 macOS High Sierra v10.13

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234