Back to list
CVE-2017-3167: Apache httpd 2.x ap_get_basic_auth_pw authentication bypass
Jun 19 2017 10:19PM
Jacob Champion (jchampion apache org)
CVE-2017-3167: ap_get_basic_auth_pw authentication bypass
Vendor: The Apache Software Foundation
httpd 2.2.0 to 2.2.32
httpd 2.4.0 to 2.4.25
Use of the ap_get_basic_auth_pw() by third-party modules outside of the
authentication phase may lead to authentication requirements being
2.2.x users should either apply the patch available at
or upgrade in the future to 2.2.33, which is currently unreleased.
2.4.x users should upgrade to 2.4.26.
Third-party module writers SHOULD use ap_get_basic_auth_components(),
available in 2.2.33 and 2.4.26, instead of ap_get_basic_auth_pw().
Modules which call the legacy ap_get_basic_auth_pw() during the
authentication phase MUST either immediately authenticate the user after
the call, or else stop the request immediately with an error response,
to avoid incorrectly authenticating the current request.
The Apache HTTP Server security team would like to thank Emmanuel
Dreyfus for reporting this issue.
[ reply ]
Copyright 2010, SecurityFocus