CVE-2017-15715
Published: 26 March 2018
In Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could match '$' to a newline character in a malicious filename, rather than matching only the end of the filename. This could be exploited in environments where uploads of some files are are externally blocked, but only by matching the trailing portion of the filename.
Priority
CVSS 3 base score: 8.1
Status
Package | Release | Status |
---|---|---|
apache2 Launchpad, Ubuntu, Debian |
Upstream |
Released
(2.4.30)
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Released
(2.4.29-1ubuntu4.1)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Released
(2.4.18-2ubuntu3.8)
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Released
(2.4.7-1ubuntu4.20)
|
|
Patches: Upstream: https://svn.apache.org/viewvc?view=revision&revision=1824339 Upstream: https://svn.apache.org/viewvc?view=revision&revision=1824439 Upstream: https://svn.apache.org/viewvc?view=revision&revision=1824472 (2.4) |