Apache – CVE-2017-9789

Description

Kayran has detected that the Version of Apache HTTP Server being used has a ‘Read after free in mod_http2’.

CVE-2017-9789 is categorized as a ‘Use After Free’ vulnerability (CWE-416).
A Use After Free occurs when we Reference memory after it has been freed. That can cause a program to crash, use unexpected values, or to execute codes.

If under stress, closing many connections, the HTTP/2 handling code in your Apache’s Version would sometimes access memory after it has been freed.
That may lead to unwanted results and and erratic behavior.

It could lead to a decrease in performance and interruptions in the availability of resources.

Recommendation

To fix CVE-2017-9789, upgrade the version of Apache HTTP Server being used to 2.4.27.

References

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9789

https://cwe.mitre.org/data/definitions/416.html

< Return to all Vulnerabilities

Browser Exploitation

We know that it’s possible to exploit weaknesses (or vulnerabilities) that exist in anything, from a certain code to the entire application, let’s talk about

Read More »

SQLI to RCE

How to preform SQLI TO RCE? One of the most interesting and important things about any site is the database. So, it’s important to protect

Read More »

What is Kayran

Kayran scanner is helping all businesses, both SMBs and enterprises, to test their online assets and products for over 30,000+ vulnerabilities.Kayran’s mission is to make

Read More »