UBUNTU-CVE-2016-0736
Dashboard / Vulnerabilities / UBUNTU-CVE-2016-0736
UBUNTU-CVE-2016-0736
Summary:
Details: In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly either CBC or ECB modes of operation (AES256-CBC by default), hence no selectable or builtin authenticated encryption. This made it vulnerable to padding oracle attacks, particularly with CBC.
References: https://ubuntu.com/security/CVE-2016-0736, https://lists.apache.org/thread.html/139862b41c0dfd5e6e00ad89c00119f9faf0dd41a2f927da9c9a4076@%3Cannounce.httpd.apache.org%3E, https://httpd.apache.org/security/vulnerabilities_24.html, https://ubuntu.com/security/notices/USN-3279-1, https://www.cve.org/CVERecord?id=CVE-2016-0736
Affected packages
Package
Name: apache2
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
