{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-02T07:23:54.029","vulnerabilities":[{"cve":{"id":"CVE-2017-15710","sourceIdentifier":"security@apache.org","published":"2018-03-26T15:29:00.227","lastModified":"2024-11-21T03:15:03.740","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-Language header value to lookup the right charset encoding when verifying the user's credentials. If the header value is not present in the charset conversion table, a fallback mechanism is used to truncate it to a two characters value to allow a quick retry (for example, 'en-US' is truncated to 'en'). A header value of less than two characters forces an out of bound write of one NUL byte to a memory location that is not part of the string. In the worst case, quite unlikely, the process would crash which could be used as a Denial of Service attack. In the more likely case, this memory is already reserved for future use and the issue has no effect at all."},{"lang":"es","value":"Si mod_authnz_ldap se configura con AuthLDAPCharsetConfig, en las versiones 2.0.23 hasta la 2.0.65, versiones 2.2.0 hasta la 2.2.34 y versiones 2.4.0 hasta la 2.4.29 en Apache httpd, usa el valor de cabecera Accept-Language para buscar la codificación de charset adecuado cuando se verifican las credenciales de usuario. Si el valor de la cabecera no está presente en la tabla de conversión de charset, se utiliza un mecanismo alternativo para truncarlo en un valor de dos caracteres para permitir que se efectúe un quick retry (por ejemplo, 'en-US' se trunca a 'en'). Un valor de cabecera inferior a dos caracteres fuerza una lectura fuera de límites de un byte NULL a una ubicación de memoria que no forma parte de la cadena. En el peor de los casos, aunque poco probable, el proceso se bloquearía, lo que se podría utilizar como un ataque denegación de servicio (DoS). Es mucho más probable que esta memoria ya esté reservada para su uso futuro y que el problema no tenga ningún tipo de impacto."}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-787"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apache:http_server:2.4.1:*:*:*:*:*:*:*","matchCriteriaId":"6FCD3C8C-9BF8-4F30-981A-593EEAEB9EDD"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:http_server:2.4.2:*:*:*:*:*:*:*","matchCriteriaId":"046487A3-752B-4D0F-8984-96486B828EAB"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:http_server:2.4.3:*:*:*:*:*:*:*","matchCriteriaId":"89D2E052-51CD-4B57-A8B8-FAE51988D654"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:http_server:2.4.4:*:*:*:*:*:*:*","matchCriteriaId":"EAA27058-BACF-4F94-8E3C-7D38EC302EC1"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:http_server:2.4.6:*:*:*:*:*:*:*","matchCriteriaId":"8FEAB0DF-04A9-4F99-8666-0BADC5D642B8"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:http_server:2.4.7:*:*:*:*:*:*:*","matchCriteriaId":"E7D924D1-8A36-4C43-9E56-52814F9A6350"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:http_server:2.4.9:*:*:*:*:*:*:*","matchCriteriaId":"39CDFECC-E26D-47E0-976F-6629040B3764"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:http_server:2.4.10:*:*:*:*:*:*:*","matchCriteriaId":"E3ECBCB1-0675-41F5-857B-438F36925F63"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:http_server:2.4.12:*:*:*:*:*:*:*","matchCriteriaId":"CB6CBFBF-74F6-42AF-BC79-AA53EA75F00B"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:http_server:2.4.16:*:*:*:*:*:*:*","matchCriteriaId":"8717A96B-9DB5-48D6-A2CF-A5E2B26AF3F3"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:http_server:2.4.17:*:*:*:*:*:*:*","matchCriteriaId":"E1F45B27-504B-4202-87B8-BD3B094003F1"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:http_server:2.4.18:*:*:*:*:*:*:*","matchCriteriaId":"F2FB2B98-DFD2-420A-8A7F-9B288651242F"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:http_server:2.4.20:*:*:*:*:*:*:*","matchCriteriaId":"B803D25B-0A19-4569-BA05-09D58F33917C"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:http_server:2.4.23:*:*:*:*:*:*:*","matchCriteriaId":"8510442C-212F-4013-85FA-E0AB59F6F2C6"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:http_server:2.4.25:*:*:*:*:*:*:*","matchCriteriaId":"FB5673AB-53BB-40B2-83A7-8B82B2D0EBB8"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:http_server:2.4.26:*:*:*:*:*:*:*","matchCriteriaId":"FBB3ED63-45CA-44AB-973C-9AD2569AD800"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:http_server:2.4.27:*:*:*:*:*:*:*","matchCriteriaId":"FF30AD98-9CBA-456E-A827-79FCEDEB30A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:http_server:2.4.28:*:*:*:*:*:*:*","matchCriteriaId":"C117BF2F-1E5B-4AEC-8770-3153E5B4CD07"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:http_server:2.4.29:*:*:*:*:*:*:*","matchCriteriaId":"437BC6D8-D103-452C-9C86-D89FC977A50F"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*","matchCriteriaId":"16F59A04-14CF-49E2-9973-645477EA09DA"},{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*","matchCriteriaId":"C11E6FB0-C8C0-4527-9AA0-CB9B316F8F43"},{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*","matchCriteriaId":"DEECE5FC-CACF-4496-A3E7-164736409252"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*","matchCriteriaId":"8D305F7A-D159-4716-AB26-5E38BB5CD991"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*","matchCriteriaId":"B5A6F2F3-4894-4392-8296-3B8DD2679084"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*","matchCriteriaId":"F7016A2A-8365-4F1A-89A2-7A19F2BCAE5B"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:*","matchCriteriaId":"9070C9D8-A14A-467F-8253-33B966C16886"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*","matchCriteriaId":"23A7C53F-B80F-4E6A-AFA9-58EEA84BE11D"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:netapp:santricity_cloud_connector:-:*:*:*:*:*:*:*","matchCriteriaId":"AB15BCF1-1B1D-49D8-9B76-46DCB10044DB"},{"vulnerable":true,"criteria":"cpe:2.3:a:netapp:storage_automation_store:-:*:*:*:*:*:*:*","matchCriteriaId":"7B7A6697-98CC-4E36-93DB-B7160F8399F9"},{"vulnerable":true,"criteria":"cpe:2.3:a:netapp:storagegrid:-:*:*:*:*:*:*:*","matchCriteriaId":"8ADFF451-740F-4DBA-BD23-3881945D3E40"},{"vulnerable":true,"criteria":"cpe:2.3:o:netapp:clustered_data_ontap:-:*:*:*:*:*:*:*","matchCriteriaId":"1FED6CAE-D97F-49E0-9D00-1642A3A427B4"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*","matchCriteriaId":"2F6AB192-9D7D-4A9A-8995-E53A9DE9EAFC"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*","matchCriteriaId":"142AD0DD-4CF3-4D74-9442-459CE3347E3A"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux:7.4:*:*:*:*:*:*:*","matchCriteriaId":"041F9200-4C01-4187-AE34-240E8277B54D"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux:7.5:*:*:*:*:*:*:*","matchCriteriaId":"4EB48767-F095-444F-9E05-D9AC345AB803"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux:7.6:*:*:*:*:*:*:*","matchCriteriaId":"5F6FA12B-504C-4DBF-A32E-0548557AA2ED"}]}]}],"references":[{"url":"http://www.openwall.com/lists/oss-security/2018/03/24/8","source":"security@apache.org","tags":["Mailing List","Third Party Advisory"]},{"url":"http://www.securityfocus.com/bid/103512","source":"security@apache.org","tags":["Third Party Advisory","VDB Entry"]},{"url":"http://www.securitytracker.com/id/1040569","source":"security@apache.org","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://access.redhat.com/errata/RHSA-2018:3558","source":"security@apache.org","tags":["Third Party Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2019:0366","source":"security@apache.org","tags":["Third Party Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2019:0367","source":"security@apache.org","tags":["Third Party Advisory"]},{"url":"https://httpd.apache.org/security/vulnerabilities_24.html","source":"security@apache.org","tags":["Vendor Advisory"]},{"url":"https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E","source":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E","source":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r04e89e873d54116a0635ef2f7061c15acc5ed27ef7500997beb65d6f%40%3Ccvs.httpd.apache.org%3E","source":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r06f0d87ebb6d59ed8379633f36f72f5b1f79cadfda72ede0830b42cf%40%3Ccvs.httpd.apache.org%3E","source":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r6521a7f62276340eabdb3339b2aa9a38c5f59d978497a1f794af53be%40%3Ccvs.httpd.apache.org%3E","source":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3E","source":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E","source":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E","source":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E","source":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/re1e3a24664d35bcd0a0e793e0b5fc6ca6c107f99a1b2c545c5d4b467%40%3Ccvs.httpd.apache.org%3E","source":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E","source":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E","source":"security@apache.org"},{"url":"https://lists.debian.org/debian-lts-announce/2018/05/msg00020.html","source":"security@apache.org","tags":["Mailing List","Third Party Advisory"]},{"url":"https://security.netapp.com/advisory/ntap-20180601-0004/","source":"security@apache.org","tags":["Third Party Advisory"]},{"url":"https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03909en_us","source":"security@apache.org","tags":["Third Party Advisory"]},{"url":"https://usn.ubuntu.com/3627-1/","source":"security@apache.org","tags":["Third Party Advisory"]},{"url":"https://usn.ubuntu.com/3627-2/","source":"security@apache.org","tags":["Third Party Advisory"]},{"url":"https://usn.ubuntu.com/3937-2/","source":"security@apache.org","tags":["Third Party Advisory"]},{"url":"https://www.debian.org/security/2018/dsa-4164","source":"security@apache.org","tags":["Third Party Advisory"]},{"url":"https://www.tenable.com/security/tns-2019-09","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2018/03/24/8","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"]},{"url":"http://www.securityfocus.com/bid/103512","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"http://www.securitytracker.com/id/1040569","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://access.redhat.com/errata/RHSA-2018:3558","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2019:0366","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2019:0367","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://httpd.apache.org/security/vulnerabilities_24.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r04e89e873d54116a0635ef2f7061c15acc5ed27ef7500997beb65d6f%40%3Ccvs.httpd.apache.org%3E","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r06f0d87ebb6d59ed8379633f36f72f5b1f79cadfda72ede0830b42cf%40%3Ccvs.httpd.apache.org%3E","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r6521a7f62276340eabdb3339b2aa9a38c5f59d978497a1f794af53be%40%3Ccvs.httpd.apache.org%3E","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3E","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/re1e3a24664d35bcd0a0e793e0b5fc6ca6c107f99a1b2c545c5d4b467%40%3Ccvs.httpd.apache.org%3E","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2018/05/msg00020.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"]},{"url":"https://security.netapp.com/advisory/ntap-20180601-0004/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03909en_us","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://usn.ubuntu.com/3627-1/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://usn.ubuntu.com/3627-2/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://usn.ubuntu.com/3937-2/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://www.debian.org/security/2018/dsa-4164","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://www.tenable.com/security/tns-2019-09","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}